WordPress Schedule Post Changes With PublishPress Future Plugin Missing Authorization Vulnerability

Vulnerability

A vulnerability exists in the WordPress Schedule Post Changes With PublishPress Future plugin, specifically in versions through 4.9.2. The issue arises from a missing capability check in the getAuthors function, allowing authenticated attackers with Contributor-level access or higher to access the email addresses of all users who have the edit_posts capability.

Impact

Exploitation of this vulnerability leads to unauthorized access to email addresses of users with edit_posts capability.

Remediation

Users can update to version 4.9.3 or a newer patched version to address this vulnerability.

Added: Dec 16, 2025, 12:17 PM
Updated: Dec 16, 2025, 2:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.9
remediation
7.7
relevance
1.4
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.