PT-2026-79531 · WordPress · Post Duplicator

·

CVE-2026-4245

·

Published

2026-08-22

·

Updated

2026-08-24

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Post Duplicator versions prior to 3.0.12
Description An authorization bypass exists due to the duplicate post permissions() permission callback verifying only the duplicate posts capability while failing to check for publish posts or other status-gated capabilities. This allows authenticated users with Contributor-level access or higher to create duplicate posts with future (scheduled for auto-publishing) or private status, thereby bypassing editorial review. Furthermore, the REST endpoint fails to enforce administrator-configured restrictions on post-type duplication, enabling the duplication of post types that were explicitly disabled.
Recommendations Update Post Duplicator to version 3.0.12 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4245

Affected Products

Post Duplicator