IMPress for IDX Broker <= 2.6.1 - Authenticated Arbitrary Post Creation, Modification, and Deletion

Missing Authorization
CVE CVE-2020-9514
CVSS High (8.1)
Publicly Published March 26, 2020
Last Updated January 22, 2024
Researcher Ram
Description

An issue was discovered in the IMPress for IDX Broker plugin before 2.6.2 for WordPress. wrappers.php allows a logged-in user (with the Subscriber role) to permanently delete arbitrary posts and pages, create new posts with arbitrary subjects, and modify the subjects of existing posts and pages (via create_dynamic_page and delete_dynamic_page). This is due to missing capability and nonce checks on two of its Ajax actions.

References

1 affected software package

Software Type Plugin
Software Slug idx-broker-platinum (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.6.2
Patched Version
  • 2.6.2
This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License Detail.