PT-2026-26827 · WordPress · Company Posts For Linkedin

Abhirup Konwar

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2026-1935

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Company Posts for LinkedIn plugin for WordPress versions prior to 1.0.1
Description The software is susceptible to a missing authorization issue. This is caused by a missing capability check within the linkedin company post reset handler() function, which is connected to the admin post reset linkedin company post action. Attackers with Subscriber-level access or higher can delete LinkedIn post data stored in the site’s options table.
Recommendations Update The Company Posts for LinkedIn plugin for WordPress to version 1.0.1 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1935

Affected Products

Company Posts For Linkedin