Description
The Permalinks Cascade plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action in the handleTPCAdminAjaxRequest function. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized administrative actions such as enabling or disabling automatic pinging settings and modifying page exclusion settings.
Problem types
Product status
* (semver)
Timeline
| 2025-11-17: | Disclosed |
Credits
Nabil Irawan
References
www.wordfence.com/...-d521-4215-9ef7-b5d1c44a19d3?source=cve
plugins.trac.wordpress.org/...min/admin-controller.class.php
plugins.trac.wordpress.org/...gs/2.2/includes/core.class.php