PT-2026-79307 · WordPress · Duplicate Post
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Duplicate Post WordPress plugin versions prior to 1.5.6
Description
Insufficient validation occurs when duplicating posts, as the plugin fails to verify if the user has permission to read the content before the duplication process. This allows users with delegated roles to republish password-protected posts created by other users, making the content publicly readable.
Recommendations
Update Duplicate Post WordPress plugin to version 1.5.6 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Duplicate Post