Bootstrapped Ventures Custom Related Posts
cpe:2.3:a:brechtvds:custom_related_posts:*:*:*:*:wordpress:*:*
- <= 1.7.3
A vulnerability exists in the Custom Related Posts plugin for WordPress, affecting all versions through 1.7.3. The issue arises from a lack of proper capability checks on three AJAX actions, allowing authenticated attackers with Subscriber-level access and above to unauthorized access and modification of data. Exploitation of this vulnerability enables these attackers to search private posts and manipulate related post relationships.
Exploitation allows for unauthorized access to private posts and the ability to link or unlink post relationships, potentially disrupting content organization and visibility.
Users are advised to update the Custom Related Posts plugin to version 1.7.4 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.