CVE-2026-14923

Sync Post With Other Site < 1.9.3 - Contributor+ Arbitrary Page Creation/Modification

The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users.


We have discovered 817 live websites that are affected by CVE-2026-14923.

Run a Free Instant Scan




Affected Software

Product  Sync Post With Other Site
Category Wordpress Plugins
Vulnerable Domains817 live websites (100% of Sync Post With Other Site install base)
Vulnerable Versions
  • from 0 through 1.9.3
Vulnerable Versions Count11 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Shikhali Jamalzade (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-14923
United States258 websites



Germany102 websites
Iran68 websites
Italy39 websites
GB33 websites
Netherlands29 websites
France22 websites
Switzerland22 websites
Brazil21 websites
Australia17 websites

Website Distribution by TLD

Number of websites using CVE-2026-14923
.com289 websites
.de71 websites
.org43 websites
.it30 websites
.eu23 websites
.nl23 websites
.net18 websites
.com.br18 websites
.fr14 websites
.co.uk14 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14923

Top websites that are affected by CVE-2026-14923. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.pl Poland**,***
**********.org United States***,***
****.net United States***,***
************.org United States***,***
*************.com United States***,***
**********.org France***,***
**********.com United States***,***
*************.dk Denmark***,***
******.*******.edu United States***,***
******.org Germany***,***
See full domain list

FAQ

CVE-2026-14923 is Incorrect Authorization in Sync Post With Other Site
A total of 817 websites have been identified as vulnerable to CVE-2026-14923, based on global website indexing conducted by WebTechSurvey.
The Sync Post With Other Site is affected by the CVE-2026-14923 vulnerability.
Sync Post With Other Site versions up to 1.9.3 are vulnerable to CVE-2026-14923.
CVE-2026-14923 is resolved in version 1.9.3 of Sync Post With Other Site.