PT-2026-79531 · WordPress · Post Duplicator
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Post Duplicator versions prior to 3.0.12
Description
An authorization bypass exists due to the
duplicate post permissions() permission callback verifying only the duplicate posts capability while failing to check for publish posts or other status-gated capabilities. This allows authenticated users with Contributor-level access or higher to create duplicate posts with future (scheduled for auto-publishing) or private status, thereby bypassing editorial review. Furthermore, the REST endpoint fails to enforce administrator-configured restrictions on post-type duplication, enabling the duplication of post types that were explicitly disabled.Recommendations
Update Post Duplicator to version 3.0.12 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Post Duplicator