The Bulk Datetime Change WordPress plugin before 1.12...
Moderate severity
Unreviewed
Published
Nov 30, 2021
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Nov 29, 2021
Published to the GitHub Advisory Database
Nov 30, 2021
Last updated
Jan 28, 2023
The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.
References