Custom Related Posts WordPress Plugin Missing Authorization Vulnerability

Vulnerability

A vulnerability exists in the Custom Related Posts plugin for WordPress, affecting all versions through 1.7.3. The issue arises from a lack of proper capability checks on three AJAX actions, allowing authenticated attackers with Subscriber-level access and above to unauthorized access and modification of data. Exploitation of this vulnerability enables these attackers to search private posts and manipulate related post relationships.

Impact

Exploitation allows for unauthorized access to private posts and the ability to link or unlink post relationships, potentially disrupting content organization and visibility.

Remediation

Users are advised to update the Custom Related Posts plugin to version 1.7.4 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.3
exploitability
6.1
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.