What is CVE-2026-14305?
This vulnerability exists in the WP Delicious WordPress plugin before version 1.10.2. A missing authorization check on an AJAX action allows unauthenticated users to modify limited post metadata (like counter and associated identifier list) on arbitrary posts. Update the plugin to version 1.10.2 or later.
Azərbaycanca: Bu boşluq WP Delicious WordPress plaginində 1.10.2 versiyasından əvvəl mövcuddur. Müəyyən bir AJAX əməliyyatında avtorizasiya yoxlanışının olmaması səbəbindən autentifikasiya olunmamış istifadəçilər ixtiyari yazıların meta məlumatlarını (bəyənmə sayğacı və əlaqəli identifikator siyahısı) dəyişə bilər. Plagin ən azı 1.10.2 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Through what operation can the CVE-2026-14305 vulnerability in the WP Delicious plugin be exploited?
The vulnerability is exploited through a specific AJAX action that lacks an authorization check.
What data can an unauthenticated user modify through this vulnerability?
They can modify limited post metadata on arbitrary posts, such as the like counter and associated identifier list.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.