plugin

Copy Delete Posts Vulnerabilities

7 known security issues reported for the Copy Delete Posts WordPress plugin. Most recent disclosed Aug 24, 2026.

7 medium

Running Copy Delete Posts on your site? Check whether your installed version is affected.

Scan your site free

Duplicate Post < 1.5.6 - Missing Authorization

medium

The Duplicate Post plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.5.6. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with author-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.5.6
Fixed in:
1.5.6
Disclosed:
Aug 24, 2026

CVE-2026-19085 on NVD →

Duplicate Post < 1.5.6 - Missing Authorization

medium

The Duplicate Post plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.5.6. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.5.6
Fixed in:
1.5.6
Disclosed:
Aug 24, 2026

CVE-2026-19435 on NVD →

Inisev Analyst Module <= Various Versions - Missing Authorization

medium

Multiple plugins and/or themes by Inisev for WordPress are vulnerable to unauthorized access due to a missing capability check on several functions in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.

CVSS:
4.3
Affected:
up to 1.4.4
Fixed in:
1.4.5
Disclosed:
Apr 10, 2024

CVE-2024-31435 on NVD →

Duplicate Post <= 1.4.1 - Cross-Site Request Forgery via 'cdp_action_handling' AJAX action

medium

The Duplicate Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1. This is due to missing or incorrect nonce validation on the 'cdp_action_handling' AJAX action. This makes it possible for unauthenticated attackers to change plugin settings, duplicate posts, and...

CVSS:
6.3
Affected:
up to 1.4.1
Fixed in:
1.4.2
Disclosed:
Aug 3, 2023

Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function

medium

Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers t...

CVSS:
4.3
Affected:
up to 1.3.9
Fixed in:
1.4.0
Disclosed:
Jul 27, 2023

CVE-2023-3977 on NVD →

Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function

medium

Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, su...

CVSS:
4.3
Affected:
up to 1.3.9
Fixed in:
1.4.0
Disclosed:
Jul 27, 2023

CVE-2023-0958 on NVD →

Duplicate Post WordPress Plugin <= 1.1.9 - SQL Injection

medium

The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Injection can typically be exploited to read, modify and delete SQL table data. In many cases it also poss...

CVSS:
6.5
Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Oct 19, 2021

CVE-2021-43408 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database