Description
WordPress Plugin PublishPress Future: Automatically Unpublish WordPress Posts is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently schedule deletion of arbitrary posts. WordPress Plugin PublishPress Future: Automatically Unpublish WordPress Posts version 2.5.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.6.0 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:DE51B970-AB13-41A6-A479-A92CD0E70B71
https://plugins.svn.wordpress.org/post-expirator/trunk/readme.txt
Related Vulnerabilities
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20411)
WordPress Plugin WP Symposium Multiple Vulnerabilities (14.10)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5472)
MySQL CVE-2015-0439 Vulnerability (CVE-2015-0439)
Apache Traffic Server Exposure of Resource to Wrong Sphere Vulnerability (CVE-2018-8040)