plugin

Post Duplicator Vulnerabilities

18 known security issues reported for the Post Duplicator WordPress plugin. Most recent disclosed Aug 21, 2026.

2 high 8 medium

Running Post Duplicator on your site? Check whether your installed version is affected.

Scan your site free

Post Duplicator <= 3.0.11 - Authorization Bypass to Authenticated (Contributor+) Post Duplication

medium

The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capability without checking whether the requesting user holds `publish_posts` or other s...

CVSS:
4.3
Affected:
up to 3.0.11
Fixed in:
3.0.12
Disclosed:
Aug 21, 2026

CVE-2026-4245 on NVD →

Post Duplicator <= 3.0.11 - Missing Authorization to Authenticated (Contributor+) Post Duplication with Arbitrary Author Attribution

medium

The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `duplicate_post()` function in all versions up to, and including, 3.0.11. This is due to the function not verifying that the user has `edit_others_posts` capability before accepting a `se...

CVSS:
4.3
Affected:
up to 3.0.11
Fixed in:
3.0.12
Disclosed:
Aug 21, 2026

CVE-2026-4244 on NVD →

Post Duplicator < 3.0.15 - Authenticated (Contributor+) PHP Object Injection

high

The Post Duplicator plugin for WordPress is vulnerable to PHP Object Injection in versions up to 3.0.15 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. I...

CVSS:
7.5
Affected:
up to 3.0.15
Fixed in:
3.0.15
Disclosed:
Jun 25, 2026

CVE-2026-10749 on NVD →

Post Duplicator <= 3.0.10 - Authenticated (Contributor+) PHP Object Injection

high

The Post Duplicator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.10 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulner...

CVSS:
7.5
Affected:
up to 3.0.10
Fixed in:
3.0.11
Disclosed:
Apr 13, 2026

CVE-2026-39474 on NVD →

Post Duplicator <= 3.0.8 - Missing Authorization to Authenticated (Contributor+) Protected Post Meta Insertion via 'customMetaData' Parameter

medium

The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all versions up to, and including, 3.0.8. This is due to the `duplicate_post()` function in `includes/api.php` using `$wpdb->insert()` directly to the `wp_postmeta` table instead of WordPress's standard `ad...

CVSS:
4.3
Affected:
up to 3.0.8
Fixed in:
3.0.9
Disclosed:
Feb 24, 2026

CVE-2026-2301 on NVD →

Post Duplicator <= 2.35 - Missing Authorization

medium

The Post Duplicator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.35
Fixed in:
2.36
Disclosed:
Jan 24, 2025

CVE-2025-24736 on NVD →

Post Duplicator [post-duplicator] < 2.36

unknown

[en] Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post Duplicator: from n/a through 2.35.

Affected:
up to 2.36
Fixed in:
2.36
Disclosed:
Jan 24, 2025

CVE-2025-24736 on NVD →

Post Duplicator [post-duplicator] < 2.37

unknown

[en] The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above, to...

Affected:
up to 2.37
Fixed in:
2.37
Disclosed:
Jan 11, 2025

CVE-2024-12472 on NVD →

Post Duplicator <= 2.36 - Authenticated (Contributor+) Protected Post Disclosure

medium

The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above...

CVSS:
4.3
Affected:
up to 2.36
Fixed in:
2.37
Disclosed:
Jan 10, 2025

CVE-2024-12472 on NVD →

Post Duplicator [post-duplicator] < 2.32

unknown

[en] Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Duplicator: from n/a through 2.31.

Affected:
up to 2.32
Fixed in:
2.32
Disclosed:
Dec 9, 2024

CVE-2023-49835 on NVD →

Post Duplicator <= 2.31 - Missing Authorization via mtphr_duplicate_post

medium

The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mtphr_duplicate_post function in versions up to, and including, 2.31. This makes it possible for authenticated attackers, with contributor-level access and above, to publish posts upon du...

CVSS:
4.3
Affected:
up to 2.31
Fixed in:
2.32
Disclosed:
Dec 5, 2023

CVE-2023-49835 on NVD →

Post Duplicator [post-duplicator] < 2.19

unknown

[en] A vulnerability was found in meta4creations Post Duplicator Plugin 2.18 on WordPress. It has been classified as problematic. Affected is the function mtphr_post_duplicator_notice of the file includes/notices.php. The manipulation of the argument post-duplicated leads to cross site scripting. It is possible to laun...

Affected:
up to 2.19
Fixed in:
2.19
Disclosed:
Feb 20, 2023

CVE-2016-15027 on NVD →

Post Duplicator [post-duplicator] < 2.27

unknown

[en] A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box executes whenever the user opens the Settings Page of the Post Duplicator Plugin or the application...

Affected:
up to 2.27
Fixed in:
2.27
Disclosed:
Mar 9, 2022

CVE-2021-33852 on NVD →

Post Duplicator <= 2.23 - Cross-Site Scripting

medium

A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box executes whenever the user opens the Settings Page of the Post Duplicator Plugin or the application root...

CVSS:
6.4
Affected:
up to 2.24
Fixed in:
2.24
Disclosed:
Dec 2, 2021

CVE-2021-33852 on NVD →

Post Duplicator <= 2.16 - Reflected Cross-Site Scripting

medium

The Post Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.16 due to insufficient input sanitization and output escaping on the 'post-duplicated' parameter. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 2.16
Fixed in:
2.17
Disclosed:
Apr 6, 2016

CVE-2016-15027 on NVD →

Post Duplicator [post-duplicator] < 2.17

unknown

The Post Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.16 due to insufficient input sanitization and output escaping on the 'post-duplicated' parameter. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 2.17
Fixed in:
2.17
Disclosed:
Apr 6, 2016

Post Duplicator [post-duplicator] < 2.17

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Upgrade the plugin.

Affected:
up to 2.17
Fixed in:
2.17
Disclosed:
Apr 6, 2016

Post Duplicator [post-duplicator] < 2.17

unknown

The Post Duplicator WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.17
Fixed in:
2.17

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database