CVE-2026-4431
critical
📛 Threat Title
Easy Post Submission <= 2.3.0 - Missing Authorization
Description
The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv_rbsm_submit_post` without any authorization checks when a `postId` parameter is supplied. This makes it possible for unauthenticated attackers to modify the title, content, excerpt, categories, and tags of arbitrary posts, as well as change the post status to draft (effectively unpublishing them) via the 'postId' parameter. Affected software — plugin: Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress (affected: *-2.3.0). CVSS 9.1 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
cve
CVE-2026-4431
IOC database
- Type
- cve
- Value
CVE-2026-4431- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Easy Post Submission <= 2.3.0 - Missing Authorization
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
Remediations (9)
-
web:askubuntu.com
Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE - 2026 -31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04. 2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.
-
web:blog.cloudflare.com
The upstream fix (commit a664bf3d603d) reverts the 2017 in-place optimization, removing the exploit. How we responded ... Incident timeline and impact ... How did we mitigate it? ... The bug was in the algif_aead kernel module. ... This mitigation was therefore exactly what the Copy Fail write-up from the security researchers who identified it ...
-
web:blog.cloudlinux.com
CVE - 2026 -31431 (Copy Fail) is a Linux kernel local privilege escalation in algif_aead. Update CloudLinux 7h, 8, 9, and 10 — KernelCare live patches available.
-
web:cert.europa.eu
Summary On 29 April 2026 , a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE - 2026 -31431 and named "Copy Fail", was publicly disclosed [1].
-
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
-
web:ubuntu.com
A proof-of-concept exploit has not been published yet. Mitigation regression risk Update: The Ubuntu Security Team has released a mitigation when this vulnerability was publicly disclosed as a temporary measure. As Linux kernel packages which implement the fixes are now available, the mitigation will be reverted.
-
web:windowsforum.com
CISA added CVE - 2026 -31431, a Linux kernel local privilege escalation flaw known as "Copy Fail," to its Known Exploited Vulnerabilities Catalog on May 1, 2026 , after evidence of active exploitation, triggering mandatory remediation for U.S. federal civilian agencies under BOD 22-01. The move...
-
web:www.kodemsecurity.com
CVE - 2026 -31431, the Copy Fail Linux kernel LPE, lets authenticated users gain root. See affected kernels, exploit details, IOCs and patches.
-
Wordfence remediation: Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPressWordfence
Update to version 2.4.0, or a newer patched version
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.