CVE-2026-78150
Received Received - Intake

Duplicate Post Privilege Escalation in Smart Post WordPress Plugin

Vulnerability report for CVE-2026-78150, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: WPScan

Description

The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the Smart Post WordPress plugin versions before 4.0.8. It allows users with contributor-level access or higher to duplicate and access private or password-protected posts without proper authorization checks. The plugin fails to verify post type, ownership, or status when duplicating posts, enabling attackers to copy sensitive content into their own drafts and read metadata.

Detection Guidance

Check if the Post Carousel plugin is installed and verify its version. If it is between 4.0.0 and 4.0.7, the system is vulnerable. Look for unauthorized post duplications or drafts created by users with contributor privileges or higher.

Impact Analysis

If you use the affected Smart Post plugin versions, an attacker with contributor access could read private or password-protected posts, including sensitive content and metadata. This could lead to unauthorized data exposure, privacy breaches, or information leaks within your WordPress site.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data in private posts without authorization. For HIPAA, it may risk unauthorized access to protected health information if such posts exist. Compliance requires ensuring only authorized users access sensitive data, which this flaw undermines.

Mitigation Strategies

Update the Post Carousel plugin to version 4.0.8 or later immediately. Remove any suspicious drafts created by unauthorized users and review user permissions to ensure contributors do not have excessive access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78150. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart