PT-2025-51474 · WordPress · Publishpress Future+1

Athiwat Tiprasaharn

·

Published

2025-12-16

·

Updated

2025-12-16

·

CVE-2025-13741

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories versions up to and including 4.9.2
Description The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin for WordPress has an issue where data can be accessed without authorization. This is due to a missing capability check on the getAuthors function. Authenticated attackers with Contributor-level access or higher can retrieve emails for all users who have the edit posts capability.
Recommendations Versions prior to and including 4.9.2 should be updated.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13741

Affected Products

Publishpress Future
Wordpress