HomeWordPress vulnerabilitiesDuplicate Post
Duplicate Post vulnerabilities
Duplicate Post has 5 known vulnerabilities in this database. The most recent published record is dated 1 Oct 2026.
- Known vulnerabilities
- 5
- Active installs
- 300,000+
- Latest version
- 1.5.7
- Last updated
- 23 Sep 2026
- Most recent
- 1 Oct 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-89424 | Medium 6.4 | Up to 1.5.6 | Fixed in a later version (latest 1.5.7) | 6 d ago |
| Broken access control CVE-2026-19085 | Low 2.7 | Before 1.5.6 | Fixed in 1.5.6 | 21 Aug 2026 |
| Sensitive data exposure CVE-2026-19435 | Low 2.7 | Before 1.5.6 | Fixed in 1.5.6 | 21 Aug 2026 |
| Broken access control CVE-2026-19077 | Medium 6.5 | Before 1.5.5 | Fixed in 1.5.5 | 10 Aug 2026 |
| SQL injection CVE-2021-43408 | Medium 6.5 | Up to 1.1.9 | Fixed in a later version (latest 1.5.7) | 19 Nov 2021 |
Read the published descriptions
- CVE-2026-89424, 1 Oct 2026
- The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin's User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload. CVE record
- CVE-2026-19085, 21 Aug 2026
- The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable. CVE record
- CVE-2026-19435, 21 Aug 2026
- The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content. CVE record
- CVE-2026-19077, 10 Aug 2026
- The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users. CVE record
- CVE-2021-43408, 19 Nov 2021
- The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Injection can typically be exploited to read, modify and delete SQL table data. In many cases it also possible to exploit features of SQL server to execute system commands and/or access the local file system. This particular vulnerability can be exploited by any authenticated user who has been granted access to use the Duplicate Post plugin. By default, this is limited to Administrators, however the plugin presents the option to permit access to the Editor, Author, Contributor and Subscriber roles. CVE record
What to do if you run Duplicate Post
If you run Duplicate Post, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Duplicate Post vulnerabilities
Free. We email you when a new vulnerability is published for Duplicate Post, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.