cleantalk
Vulnerabilities and Security Researches

Duplicate Post, CVE-2026-19435

CVE, Research URL

CVE-2026-19435

Application

Duplicate Post

Published on
Aug 21, 2026
Research Description
The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content.
Affected versions
max 1.5.6.
Status
vulnerable