plugin

Duplicate Post Vulnerabilities

14 known security issues reported for the Duplicate Post WordPress plugin. Most recent disclosed Mar 18, 2026.

1 critical 5 medium

Running Duplicate Post on your site? Check whether your installed version is affected.

Scan your site free

Duplicate Post - Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite vulnerability

medium

Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite vulnerability

CVSS:
5.4
Affected:
up to 4.5
Fixed in:
4.6
Disclosed:
Mar 18, 2026

Yoast Duplicate Post <= 4.5 - Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite

medium

The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level ac...

CVSS:
5.4
Affected:
up to 4.5
Fixed in:
4.6
Disclosed:
Mar 17, 2026

CVE-2026-1217 on NVD →

Duplicate Post <= 3.2.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages...

CVSS:
4.4
Affected:
up to 3.2.3
Fixed in:
3.2.4
Disclosed:
Feb 11, 2026

CVE-2019-25314 on NVD →

Yoast Duplicate Post [duplicate-post] <= 3.2.3 (unfixed)

unknown

[en] Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings parameters. Attackers can inject malicious scripts into title prefix, suffix, menu order, and blacklist fields to execute arbitrary JavaScript in admin interfaces.

Affected:
up to 3.2.3
Fix:
No patched version reported
Disclosed:
Feb 11, 2026

CVE-2019-25314 on NVD →

Yoast Duplicate Post <= 3.2.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Yoast Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.3. This makes it possible for high-level authenticated users, such as administrators, to inject arbitrary web scripts into administrative pages via several parameters such as 'duplicate_post_...

CVSS:
5.5
Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
Sep 26, 2019

CVE-2019-25314 on NVD →

Yoast Duplicate Post [duplicate-post] < 3.2.4

unknown

The Yoast Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.3. This makes it possible for high-level authenticated users, such as administrators, to inject arbitrary web scripts into administrative pages via several parameters such as 'duplicate_post_...

Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
Sep 26, 2019

Yoast Duplicate Post [duplicate-post] < 3.0

unknown

[en] The duplicate-post plugin before 2.6 for WordPress has XSS.

Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Aug 21, 2019

CVE-2014-10378 on NVD →

Yoast Duplicate Post [duplicate-post] < 2.6

unknown

[en] The duplicate-post plugin before 2.6 for WordPress has SQL injection.

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Aug 21, 2019

CVE-2014-10379 on NVD →

Yoast Duplicate Post <= 2.5 - SQL Injection

critical

The duplicate-post plugin before 2.6 for WordPress has SQL injection.

CVSS:
9.8
Affected:
up to 2.5
Fixed in:
2.6
Disclosed:
Aug 1, 2014

CVE-2014-10379 on NVD →

Yoast Duplicate Post <= 2.6 - Cross-Site Scripting

medium

The Yoast Duplicate Post plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 2.6
Fixed in:
3.0
Disclosed:
Aug 1, 2014

CVE-2014-10378 on NVD →

Yoast Duplicate Post [duplicate-post] < 2.6

unknown

This plugin is prone to a reflected XSS in options-general.php post parameter. Update the plugin.

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Aug 1, 2014

Yoast Duplicate Post [duplicate-post] < 2.6

unknown

This plugin is prone to an SQL injection in duplicate-post-admin.php. Upgrade the plugin.

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Aug 1, 2014

Yoast Duplicate Post [duplicate-post] < 3.2.4

unknown

The Duplicate Post plugin was vulnerable to Authenticated Stored Cross-Site Scripting (XSS). However, the POST request had a CSRF nonce that was verified, and no user&#039;s without the unfiltered_html capability, such as Author or Subscriber, were able to access the affected Duplicate Post settings page. Therefore, th...

Affected:
up to 3.2.4
Fixed in:
3.2.4

Yoast Duplicate Post [duplicate-post] < 2.6

unknown

The Yoast Duplicate Post WordPress plugin was affected by an options-general.php post Parameter Reflected XSS security vulnerability.

Affected:
up to 2.6
Fixed in:
2.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database