---
id: CVE-2025-13149
title: >-
  The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change
  Status, Trash, Change Categories plugin for WordPress is vulnerable to
  unauthorized modification of data due to a missing authorization check on the
  "saveFutur…
summary: >-
  The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change
  Status, Trash, Change Categories plugin for WordPress is vulnerable to
  unauthorized modification of data due to a missing authorization check on the
  "saveFutur…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2025-11-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13149'
references:
  - url: >-
      https://github.com/publishpress/publishpress-future/commit/0cbefc1632c6f1fffc5fa0ca85e6b8a641d41c7f
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/82ea0ebc-08aa-4ef5-b6b1-c7c13715ef6d?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00188
epssPercentile: 0.07673
ingestedAt: '2026-10-08T10:28:19.992Z'
---

## Overview

The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the "saveFutureActionData" function in all versions up to, and including, 4.9.1. This makes it possible for authenticated attackers, with author level access and above, to change the status of arbitrary posts and pages via the REST API endpoint.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
