{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/easy-post-submission/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-4431"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Easy Post Submission"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the \u003ccode\u003ecreate_post()\u003c/code\u003e function, affecting all versions up to and including 2.3.0. The vulnerability resides in the \u003ccode\u003erbsm_submit_post\u003c/code\u003e AJAX action, which is registered for unauthenticated users via \u003ccode\u003ewp_ajax_nopriv_rbsm_submit_post\u003c/code\u003e. Because the plugin lacks proper authorization checks when a \u003ccode\u003epostId\u003c/code\u003e parameter is provided during a request, an unauthenticated attacker can manipulate the title, content, excerpt, categories, and tags of any existing post on the affected WordPress site. Furthermore, an attacker can change the post status to draft, effectively unpublishing content. This represents a significant risk to site integrity and availability, as unauthorized parties can deface or remove public-facing content without administrative privileges.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to modify, deface, or unpublish any post on a WordPress site running the vulnerable plugin. This can lead to site-wide content integrity loss, unauthorized information disclosure via excerpt modification, or service disruption through the unpublishing of critical posts. The vulnerability affects all users of the Easy Post Submission plugin version 2.3.0 and below.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Easy Post Submission plugin to the latest version once a patch is available or remove the plugin if a patch is not provided.\u003c/li\u003e\n\u003cli\u003eImplement WAF rules to monitor or block HTTP POST requests to \u003ccode\u003ewp-admin/admin-ajax.php\u003c/code\u003e where the action parameter is \u003ccode\u003erbsm_submit_post\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAudit WordPress post modification logs for suspicious activity occurring from unauthenticated sessions if the site is suspected to be under attack.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T09:15:32Z","date_published":"2026-08-05T09:15:32Z","id":"https://feed.craftedsignal.io/briefs/2026-08-easy-post-submission-vulnerability/","summary":"The Easy Post Submission plugin for WordPress is vulnerable to unauthorized data modification via an unauthenticated AJAX action, allowing attackers to alter or unpublish existing posts.","title":"Unauthenticated Data Modification in Easy Post Submission Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-easy-post-submission-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Easy Post Submission","version":"https://jsonfeed.org/version/1.1"}