s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-4431 critical

📛 Threat Title

Easy Post Submission <= 2.3.0 - Missing Authorization

Category: wordpress-vulnerability Published: Source updated: First seen: Last updated: Source: Wordfence

Description

The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv_rbsm_submit_post` without any authorization checks when a `postId` parameter is supplied. This makes it possible for unauthenticated attackers to modify the title, content, excerpt, categories, and tags of arbitrary posts, as well as change the post status to draft (effectively unpublishing them) via the 'postId' parameter. Affected software — plugin: Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress (affected: *-2.3.0). CVSS 9.1 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

cve CVE-2026-4431

IOC database

Type
cve
Value
CVE-2026-4431
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Easy Post Submission <= 2.3.0 - Missing Authorization

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

Remediations (9)

  • web:askubuntu.com

    Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE - 2026 -31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04. 2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.

  • web:blog.cloudflare.com

    The upstream fix (commit a664bf3d603d) reverts the 2017 in-place optimization, removing the exploit. How we responded ... Incident timeline and impact ... How did we mitigate it? ... The bug was in the algif_aead kernel module. ... This mitigation was therefore exactly what the Copy Fail write-up from the security researchers who identified it ...

  • web:blog.cloudlinux.com

    CVE - 2026 -31431 (Copy Fail) is a Linux kernel local privilege escalation in algif_aead. Update CloudLinux 7h, 8, 9, and 10 — KernelCare live patches available.

  • web:cert.europa.eu

    Summary On 29 April 2026 , a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE - 2026 -31431 and named "Copy Fail", was publicly disclosed [1].

  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

  • web:ubuntu.com

    A proof-of-concept exploit has not been published yet. Mitigation regression risk Update: The Ubuntu Security Team has released a mitigation when this vulnerability was publicly disclosed as a temporary measure. As Linux kernel packages which implement the fixes are now available, the mitigation will be reverted.

  • web:windowsforum.com

    CISA added CVE - 2026 -31431, a Linux kernel local privilege escalation flaw known as "Copy Fail," to its Known Exploited Vulnerabilities Catalog on May 1, 2026 , after evidence of active exploitation, triggering mandatory remediation for U.S. federal civilian agencies under BOD 22-01. The move...

  • web:www.kodemsecurity.com

    CVE - 2026 -31431, the Copy Fail Linux kernel LPE, lets authenticated users gain root. See affected kernels, exploit details, IOCs and patches.

  • Wordfence remediation: Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress
    Wordfence

    Update to version 2.4.0, or a newer patched version

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.