{"error":0,"message":null,"data":{"name":"Yoast Duplicate Post","plugin":"duplicate-post","link":"https:\/\/wordpress.org\/plugins\/duplicate-post\/","latest":"1787061660","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"17650b49f8f6879f419d6eec7fa5c5f349cfe243152f2a272f3c7b65a3536215","name":"Yoast Duplicate Post [duplicate-post] < 3.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-10378","name":"CVE-2014-10378","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-10378","description":"[en] The duplicate-post plugin before 2.6 for WordPress has XSS.","date":"2019-08-21"},{"id":"160d938f0ef70d45e727cdb155370e314cfe9af3","name":"Yoast Duplicate Post <= 2.6 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicate-post\/yoast-duplicate-post-26-cross-site-scripting","description":"The Yoast Duplicate Post plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2014-08-01"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"3bba7c4e3dcb86e333c514de2024dc36c06b625512be49167640769023f164f7","name":"Yoast Duplicate Post [duplicate-post] < 2.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-10379","name":"CVE-2014-10379","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-10379","description":"[en] The duplicate-post plugin before 2.6 for WordPress has SQL injection.","date":"2019-08-21"},{"id":"50f04757-f39b-4d34-b945-c5e8fd0c1afb","name":"Duplicate Post 2.5 - duplicate-post-admin.php User Login Cookie Value SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/50f04757-f39b-4d34-b945-c5e8fd0c1afb","description":"The Yoast Duplicate Post WordPress plugin was affected by a duplicate-post-admin.php User Login Cookie Value SQL Injection security vulnerability.","date":null},{"id":"33f8a04c90b9723b815f6065d9c86e8500f300ee","name":"Yoast Duplicate Post <= 2.5 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicate-post\/yoast-duplicate-post-25-sql-injection","description":"The duplicate-post plugin before 2.6 for WordPress has SQL injection.","date":"2014-08-01"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"4b35696c67169234480b6ccd897ecfbdf19cdd6b25ba23d34805f740e34f007d","name":"Yoast Duplicate Post [duplicate-post] < 2.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"adf61801002d79eedea214564cacbe007cc5acbb","name":"WordPress Duplicate Post  Plugin <= 2.5 - Reflected XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicate-post\/vulnerability\/wordpress-duplicate-post-plugin-2-5-reflected-xss","description":"This plugin is prone to a reflected XSS in options-general.php post parameter.\nUpdate the plugin.","date":"2014-08-01"}],"impact":[]},{"uuid":"78710231db1f5df37dba5f7c2846b7753f5199dc006444985e73a6c2dc314c56","name":"Yoast Duplicate Post [duplicate-post] < 2.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"377fedcab5c12bd47f36f6c07d5a3d27d7b4a3ef","name":"WordPress Duplicate Post Plugin <= 2.5 - SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicate-post\/vulnerability\/wordpress-duplicate-post-plugin-2-5-sql-injection","description":"This plugin is prone to an SQL injection in duplicate-post-admin.php.\nUpgrade the plugin.","date":"2014-08-01"}],"impact":[]},{"uuid":"ee63c10241b1ae81af96c4ba68a70d12180b4bfd63e8728b6ff03317d0f4dec2","name":"Yoast Duplicate Post [duplicate-post] < 3.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b0b1a2fc552312db93119d9c392b4cf53ab83267","name":"Yoast Duplicate Post <= 3.2.3 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicate-post\/yoast-duplicate-post-323-authenticated-admin-stored-cross-site-scripting","description":"The Yoast Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.3. This makes it possible for high-level authenticated users, such as administrators, to inject arbitrary web scripts into administrative pages via several parameters such as 'duplicate_post_title_prefix'. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2019-09-26"},{"id":"CVE-2019-25314","name":"CVE-2019-25314","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-25314","description":"[en] Yoast Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings parameters. Attackers can inject malicious scripts into title prefix, suffix, menu order, and blacklist fields to execute arbitrary JavaScript in admin interfaces.","date":"2026-02-11"},{"id":"46882f9516ed5d9c896aa19e3d6f2f1658c4d676","name":"Duplicate Post <= 3.2.3 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicate-post\/duplicate-post-323-authenticated-administrator-stored-cross-site-scripting","description":"The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2026-02-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"5.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"5.5","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2666b5e4df7b66f2640161e70839c571842936693addf2193d71637b72f6097d","name":"Yoast Duplicate Post [duplicate-post] < 3.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e73b1e92-153a-4f81-ade9-a55ffe603245","name":"Duplicate Post &lt;= 3.2.3 - Authenticated Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/e73b1e92-153a-4f81-ade9-a55ffe603245","description":"The Duplicate Post plugin was vulnerable to Authenticated Stored Cross-Site Scripting (XSS). However, the POST request had a CSRF nonce that was verified, and no user&#039;s without the unfiltered_html capability, such as Author or Subscriber, were able to access the affected Duplicate Post settings page. Therefore, this vulnerability would be very difficult to exploit in the real world. The risk of this issue is very low.","date":null}],"impact":[]},{"uuid":"557afb87e0bad667df5a58997015a2815ebe1efb706bd6b3344fff7a2455a236","name":"Yoast Duplicate Post [duplicate-post] < 2.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4ed4d9c7-d743-4d9d-bc66-fe0122178036","name":"Duplicate Post 2.5 - options-general.php post Parameter Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/4ed4d9c7-d743-4d9d-bc66-fe0122178036","description":"The Yoast Duplicate Post WordPress plugin was affected by an options-general.php post Parameter Reflected XSS security vulnerability.","date":null}],"impact":[]},{"uuid":"70904f81003f66f8ea609e7917a3e1b3605b2024e52336ac3571f30491f6d8ef","name":"Yoast Duplicate Post [duplicate-post] < 4.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1217","name":"Yoast Duplicate Post <= 4.5 - Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1217","description":"The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content.","date":"0000-00-00"},{"id":"92ba84220d5f9e3bb85fdfa5a062edfd5e82e934","name":"Yoast Duplicate Post <= 4.5 - Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicate-post\/yoast-duplicate-post-45-authenticated-contributor-missing-authorization-to-arbitrary-post-duplication-and-overwrite","description":"The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content.","date":"2026-03-17"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f5378ef97f72b1873c58dcdab1f8faf603b44f37d83af8bde3df53f39b4837e8","name":"Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-53740","name":"CVE-2026-53740","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-53740","description":"[en] Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to execute script when an administrator views the resulting notice.","date":"2026-06-10"},{"id":"EUVD-2026-36141","name":"EUVD-2026-36141","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-36141","description":"Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to execute script when an administrator views the resulting notice.","date":"2026-06-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss4":{"version":"4.0","vector":"CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:L\/UI:P\/VC:N\/VI:N\/VA:N\/SC:L\/SI:L\/SA:N","score":"5.1","severity":"medium","av":"network","ac":"low","at":"none","pr":"low","ui":"passive","vc":"none","vi":"none","va":"none","sc":"low","si":"low","sa":"none"}}},{"uuid":"8e4256c1866a3b3a1e6c9f821d285ebb7b3cbf3065d24ee59dc6f4f45d19d8c2","name":"Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-53739","name":"CVE-2026-53739","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-53739","description":"[en] Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any authenticated user into sending a request that sets the duplicate_post_show_notice site option, suppressing admin notices network-wide.","date":"2026-06-10"},{"id":"EUVD-2026-36140","name":"EUVD-2026-36140","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-36140","description":"Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any authenticated user into sending a request that sets the duplicate_post_show_notice site option, suppressing admin notices network-wide.","date":"2026-06-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss4":{"version":"4.0","vector":"CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:N\/UI:A\/VC:N\/VI:L\/VA:N\/SC:N\/SI:N\/SA:N","score":"5.1","severity":"medium","av":"network","ac":"low","at":"none","pr":"none","ui":"active","vc":"none","vi":"low","va":"none","sc":"none","si":"none","sa":"none"}}}]},"updated":"1785844364"}