Executive brief
RPS Include Content is a WordPress plugin used to display content from one page or post within another. A security flaw in this plugin allows users with low-level access, such as contributors, to bypass intended security restrictions and view or modify content they should not be able to access. This could lead to the exposure of private information or unauthorized changes to website content.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the redpixelstudios RPS Include Content plugin (rps-include-content) through version 1.2.2. The flaw stems from incorrectly configured access control security levels within the plugin's functionality. An authenticated attacker with 'Contributor' or higher privileges can exploit this to perform actions or access data that should be restricted to higher-privileged roles. As of the advisory date, no official patch has been released, and the vulnerability remains unpatched in version 1.2.2.
Affected products
- redpixelstudios RPS Include Content <= 1.2.2
Timeline
- 2026-01-15: other: Vulnerability reported by researcher
- 2026-02-14: advisory: Patchstack published initial advisory
- 2026-04-08: disclosed: CVE published to NVD