WP Duplicate <= 1.1.8 - Authenticated (Subscriber+) Arbitrary File Upload via 'process_add_site' AJAX Action
high
The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to a missing capability check on the `process_add_site()` AJAX action combined with path traversal in the file upload functionality. This makes it possible...
- CVSS:
- 8.8
- Affected:
- up to 1.1.8
- Fixed in:
- 1.1.9
- Disclosed:
- Feb 5, 2026
CVE-2026-1499 on NVD →
WP Duplicate – WordPress Migration Plugin <= 1.1.6 - Missing Authorization
medium
The WP Duplicate – WordPress Migration Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized acti...
- CVSS:
- 4.3
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Jan 24, 2025
CVE-2025-24652 on NVD →
WP Duplicate – WordPress Migration Plugin [local-sync] < 1.1.7
unknown
[en] Missing Authorization vulnerability in Revmakx WP Duplicate – WordPress Migration Plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Duplicate – WordPress Migration Plugin: from n/a through 1.1.6.
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
- Disclosed:
- Jan 24, 2025
CVE-2025-24652 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database