Easy Post Submission WordPress Plugin Vulnerability: Critical CVE-2026-4431
The Easy Post Submission plugin for WordPress <=2.3.0 is under investigation for a critical vulnerability that allows unauthenticated attackers to modify post details and change post status to draft.
What happened
The Easy Post Submission plugin for WordPress <=2.3.0 appears to be vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function. This vulnerability, tracked as CVE-2026-4431, allows unauthenticated attackers to modify the title, content, excerpt, categories, and tags of arbitrary posts, as well as change the post status to draft. The vulnerability is attributed to the `rbsm_submit_post` AJAX action being registered for unauthenticated users without any authorization checks when a `postId` parameter is supplied.
To assess your exposure, check if your WordPress site is using the Easy Post Submission plugin version 2.3.0 or earlier. If so, it is recommended to upgrade to a version that includes a fix for this vulnerability as soon as it becomes available. For more detailed information, consult the primary sources linked in the threat data.
How 0Day mitigates this
easy post submission plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.