← WordPress Vulnerabilities
WordPress security by component

Auto Post Scheduler

Auto Post Scheduler is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Mar 31, 2026; the highest CVE/CNA score is 6.1.

Plugin slug: auto-post-scheduler

CVE-2026-1877: Auto Post Scheduler: Cross-site request forgery

Auto Post Scheduler is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 1.84.

PublishedMar 31, 2026
Known safe version> 1.84
Safe version
Mar 31, 2026 CVE-2026-1877
Auto Post Scheduler: Cross-site request forgery
Auto Post Scheduler is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 1.84.
> 1.84
CVE6.1
NVDPending