PT-2026-8047 · WordPress · Wp Last Modified Info

Itthidej Aramsri

·

Published

2026-02-14

·

Updated

2026-02-14

·

CVE-2025-14608

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Last Modified Info plugin for WordPress versions up to and including 1.9.5
Description The WP Last Modified Info plugin for WordPress is susceptible to an Insecure Direct Object Reference issue. The plugin does not properly validate a user’s access rights to a post before altering its metadata within the 'bulk save' AJAX action. This allows authenticated attackers with Author-level access or higher to modify the last modified metadata and lock the modification date of any post, even those created by Administrators. The manipulation is performed through the post ids parameter.
Recommendations Update the WP Last Modified Info plugin to a version later than 1.9.5.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14608

Affected Products

Wp Last Modified Info