Page and Post Clone - Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter vulnerability
high
Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter vulnerability
- CVSS:
- 8.5
- Affected:
- up to 6.3
- Fixed in:
- 6.4
- Disclosed:
- Mar 4, 2026
Page and Post Clone <= 6.3 - Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter
medium
The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_clone() function in all versions up to, and including, 6.3. This is due to insufficient escaping on the user-supplied meta_key value and insufficient preparation on the existing SQL query. This makes...
- CVSS:
- 6.5
- Affected:
- up to 6.3
- Fixed in:
- 6.4
- Disclosed:
- Mar 4, 2026
CVE-2026-2893 on NVD →
Page and Post Clone [page-or-post-clone] < 6.1
unknown
[en] The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the 'content_clone' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to cl...
- Affected:
- up to 6.1
- Fixed in:
- 6.1
- Disclosed:
- Jun 29, 2024
CVE-2024-5942 on NVD →
Page and Post Clone <= 6.0 - Insecure Direct Object Reference to Authenticated (Author+) Sensitive Information Exposure
medium
The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the 'content_clone' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to clone a...
- CVSS:
- 4.3
- Affected:
- up to 6.0
- Fixed in:
- 6.1
- Disclosed:
- Jun 28, 2024
CVE-2024-5942 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database