Description
WordPress Plugin PublishPress Future: Automatically Unpublish WordPress Posts is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently schedule deletion of arbitrary posts. WordPress Plugin PublishPress Future: Automatically Unpublish WordPress Posts version 2.5.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.6.0 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:DE51B970-AB13-41A6-A479-A92CD0E70B71
https://plugins.svn.wordpress.org/post-expirator/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Frequently Bought Together Security Bypass (1.2.10)
Magento CVE-2019-8122 Vulnerability (CVE-2019-8122)
WordPress Plugin NextGEN Gallery-WordPress Gallery Multiple HTML Injection Vulnerabilities (1.9.0)
Oracle Database Server CVE-2009-0972 Vulnerability (CVE-2009-0972)