Post Duplicator <= 3.0.11 - Authorization Bypass to Authenticated (Contributor+) Post Duplication
medium
The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capability without checking whether the requesting user holds `publish_posts` or other s...
- CVSS:
- 4.3
- Affected:
- up to 3.0.11
- Fixed in:
- 3.0.12
- Disclosed:
- Aug 21, 2026
CVE-2026-4245 on NVD →
Post Duplicator <= 3.0.11 - Missing Authorization to Authenticated (Contributor+) Post Duplication with Arbitrary Author Attribution
medium
The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `duplicate_post()` function in all versions up to, and including, 3.0.11. This is due to the function not verifying that the user has `edit_others_posts` capability before accepting a `se...
- CVSS:
- 4.3
- Affected:
- up to 3.0.11
- Fixed in:
- 3.0.12
- Disclosed:
- Aug 21, 2026
CVE-2026-4244 on NVD →
Post Duplicator < 3.0.15 - Authenticated (Contributor+) PHP Object Injection
high
The Post Duplicator plugin for WordPress is vulnerable to PHP Object Injection in versions up to 3.0.15 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. I...
- CVSS:
- 7.5
- Affected:
- up to 3.0.15
- Fixed in:
- 3.0.15
- Disclosed:
- Jun 25, 2026
CVE-2026-10749 on NVD →
Post Duplicator <= 3.0.10 - Authenticated (Contributor+) PHP Object Injection
high
The Post Duplicator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.10 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulner...
- CVSS:
- 7.5
- Affected:
- up to 3.0.10
- Fixed in:
- 3.0.11
- Disclosed:
- Apr 13, 2026
CVE-2026-39474 on NVD →
Post Duplicator <= 3.0.8 - Missing Authorization to Authenticated (Contributor+) Protected Post Meta Insertion via 'customMetaData' Parameter
medium
The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all versions up to, and including, 3.0.8. This is due to the `duplicate_post()` function in `includes/api.php` using `$wpdb->insert()` directly to the `wp_postmeta` table instead of WordPress's standard `ad...
- CVSS:
- 4.3
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.9
- Disclosed:
- Feb 24, 2026
CVE-2026-2301 on NVD →
Post Duplicator <= 2.35 - Missing Authorization
medium
The Post Duplicator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.35
- Fixed in:
- 2.36
- Disclosed:
- Jan 24, 2025
CVE-2025-24736 on NVD →
Post Duplicator [post-duplicator] < 2.36
unknown
[en] Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post Duplicator: from n/a through 2.35.
- Affected:
- up to 2.36
- Fixed in:
- 2.36
- Disclosed:
- Jan 24, 2025
CVE-2025-24736 on NVD →
Post Duplicator [post-duplicator] < 2.37
unknown
[en] The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above, to...
- Affected:
- up to 2.37
- Fixed in:
- 2.37
- Disclosed:
- Jan 11, 2025
CVE-2024-12472 on NVD →
Post Duplicator <= 2.36 - Authenticated (Contributor+) Protected Post Disclosure
medium
The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above...
- CVSS:
- 4.3
- Affected:
- up to 2.36
- Fixed in:
- 2.37
- Disclosed:
- Jan 10, 2025
CVE-2024-12472 on NVD →
Post Duplicator [post-duplicator] < 2.32
unknown
[en] Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Duplicator: from n/a through 2.31.
- Affected:
- up to 2.32
- Fixed in:
- 2.32
- Disclosed:
- Dec 9, 2024
CVE-2023-49835 on NVD →
Post Duplicator <= 2.31 - Missing Authorization via mtphr_duplicate_post
medium
The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mtphr_duplicate_post function in versions up to, and including, 2.31. This makes it possible for authenticated attackers, with contributor-level access and above, to publish posts upon du...
- CVSS:
- 4.3
- Affected:
- up to 2.31
- Fixed in:
- 2.32
- Disclosed:
- Dec 5, 2023
CVE-2023-49835 on NVD →
Post Duplicator [post-duplicator] < 2.19
unknown
[en] A vulnerability was found in meta4creations Post Duplicator Plugin 2.18 on WordPress. It has been classified as problematic. Affected is the function mtphr_post_duplicator_notice of the file includes/notices.php. The manipulation of the argument post-duplicated leads to cross site scripting. It is possible to laun...
- Affected:
- up to 2.19
- Fixed in:
- 2.19
- Disclosed:
- Feb 20, 2023
CVE-2016-15027 on NVD →
Post Duplicator [post-duplicator] < 2.27
unknown
[en] A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box executes whenever the user opens the Settings Page of the Post Duplicator Plugin or the application...
- Affected:
- up to 2.27
- Fixed in:
- 2.27
- Disclosed:
- Mar 9, 2022
CVE-2021-33852 on NVD →
Post Duplicator <= 2.23 - Cross-Site Scripting
medium
A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box executes whenever the user opens the Settings Page of the Post Duplicator Plugin or the application root...
- CVSS:
- 6.4
- Affected:
- up to 2.24
- Fixed in:
- 2.24
- Disclosed:
- Dec 2, 2021
CVE-2021-33852 on NVD →
Post Duplicator <= 2.16 - Reflected Cross-Site Scripting
medium
The Post Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.16 due to insufficient input sanitization and output escaping on the 'post-duplicated' parameter. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 2.16
- Fixed in:
- 2.17
- Disclosed:
- Apr 6, 2016
CVE-2016-15027 on NVD →
Post Duplicator [post-duplicator] < 2.17
unknown
The Post Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.16 due to insufficient input sanitization and output escaping on the 'post-duplicated' parameter. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 2.17
- Fixed in:
- 2.17
- Disclosed:
- Apr 6, 2016
Post Duplicator [post-duplicator] < 2.17
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Upgrade the plugin.
- Affected:
- up to 2.17
- Fixed in:
- 2.17
- Disclosed:
- Apr 6, 2016
Post Duplicator [post-duplicator] < 2.17
unknown
The Post Duplicator WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.17
- Fixed in:
- 2.17
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database