Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesDuplicate Post

Duplicate Post vulnerabilities

Duplicate Post has 5 known vulnerabilities in this database. The most recent published record is dated 1 Oct 2026.

Known vulnerabilities
5
Active installs
300,000+
Latest version
1.5.7
Last updated
23 Sep 2026
Most recent
1 Oct 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-89424
Medium 6.4Up to 1.5.6Fixed in a later version (latest 1.5.7)6 d ago
Broken access control
CVE-2026-19085
Low 2.7Before 1.5.6Fixed in 1.5.621 Aug 2026
Sensitive data exposure
CVE-2026-19435
Low 2.7Before 1.5.6Fixed in 1.5.621 Aug 2026
Broken access control
CVE-2026-19077
Medium 6.5Before 1.5.5Fixed in 1.5.510 Aug 2026
SQL injection
CVE-2021-43408
Medium 6.5Up to 1.1.9Fixed in a later version (latest 1.5.7)19 Nov 2021
Read the published descriptions
CVE-2026-89424, 1 Oct 2026
The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin's User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload. CVE record
CVE-2026-19085, 21 Aug 2026
The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable. CVE record
CVE-2026-19435, 21 Aug 2026
The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content. CVE record
CVE-2026-19077, 10 Aug 2026
The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users. CVE record
CVE-2021-43408, 19 Nov 2021
The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Injection can typically be exploited to read, modify and delete SQL table data. In many cases it also possible to exploit features of SQL server to execute system commands and/or access the local file system. This particular vulnerability can be exploited by any authenticated user who has been granted access to use the Duplicate Post plugin. By default, this is limited to Administrators, however the plugin presents the option to permit access to the Editor, Author, Contributor and Subscriber roles. CVE record

What to do if you run Duplicate Post

If you run Duplicate Post, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Duplicate Post vulnerabilities

Free. We email you when a new vulnerability is published for Duplicate Post, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support