Duplicate Post, CVE-2026-19435
- CVE, Research URL
- Home page URL
- Application
- Published on
- Aug 21, 2026
- Research Description
- The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content.
- Affected versions
-
max 1.5.6.
- Status
-
vulnerable