Duplicate Post < 1.5.6 - Missing Authorization
medium
The Duplicate Post plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.5.6. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with author-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
- Disclosed:
- Aug 24, 2026
CVE-2026-19085 on NVD →
Duplicate Post < 1.5.6 - Missing Authorization
medium
The Duplicate Post plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.5.6. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
- Disclosed:
- Aug 24, 2026
CVE-2026-19435 on NVD →
Inisev Analyst Module <= Various Versions - Missing Authorization
medium
Multiple plugins and/or themes by Inisev for WordPress are vulnerable to unauthorized access due to a missing capability check on several functions in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.5
- Disclosed:
- Apr 10, 2024
CVE-2024-31435 on NVD →
Duplicate Post <= 1.4.1 - Cross-Site Request Forgery via 'cdp_action_handling' AJAX action
medium
The Duplicate Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1. This is due to missing or incorrect nonce validation on the 'cdp_action_handling' AJAX action. This makes it possible for unauthenticated attackers to change plugin settings, duplicate posts, and...
- CVSS:
- 6.3
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.2
- Disclosed:
- Aug 3, 2023
Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function
medium
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers t...
- CVSS:
- 4.3
- Affected:
- up to 1.3.9
- Fixed in:
- 1.4.0
- Disclosed:
- Jul 27, 2023
CVE-2023-3977 on NVD →
Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function
medium
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, su...
- CVSS:
- 4.3
- Affected:
- up to 1.3.9
- Fixed in:
- 1.4.0
- Disclosed:
- Jul 27, 2023
CVE-2023-0958 on NVD →
Duplicate Post WordPress Plugin <= 1.1.9 - SQL Injection
medium
The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Injection can typically be exploited to read, modify and delete SQL table data. In many cases it also poss...
- CVSS:
- 6.5
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
- Disclosed:
- Oct 19, 2021
CVE-2021-43408 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database