WordPress Schedule Post Changes With PublishPress Future Plugin Missing Authorization Vulnerability
Vulnerability
A vulnerability exists in the WordPress Schedule Post Changes With PublishPress Future plugin, specifically in versions through 4.9.2. The issue arises from a missing capability check in the getAuthors function, allowing authenticated attackers with Contributor-level access or higher to access the email addresses of all users who have the edit_posts capability.
Impact
Exploitation of this vulnerability leads to unauthorized access to email addresses of users with edit_posts capability.
Remediation
Users can update to version 4.9.3 or a newer patched version to address this vulnerability.
Added: Dec 16, 2025, 12:17 PM
Updated: Dec 16, 2025, 2:17 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
5.9remediation
7.7relevance
1.4threat
3.2urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
