WP Post Page Clone <= 1.1 - Missing Authorization to Post Disclosure
medium
The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view normally.
- CVSS:
- 4.3
- Affected:
- up to 1.1
- Fixed in:
- 1.2
- Disclosed:
- Dec 27, 2021
CVE-2021-24733 on NVD →
Duplicate Page Plugins <= (Various Versions) - SQL Injection
high
The Duplicate Page and Post, WP Post Page Clone and Duplicate Page plugins for WordPress are vulnerable to SQL Injection via the ‘post’ parameter in versions up to, and including, 2.5.6, 1.1, and 3.3 respectively, due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis...
- CVSS:
- 8.8
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Apr 25, 2020
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database