- Published on
-
Jan 11, 2025
- Research Description
-
The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to by duplicating the post.
- Affected versions
-
Min -, max 2.37.
Previous vulnerability researches |
Multisite Post Duplicator
(CVE-2016-10944)
, Jun 07, 2024
|
WP Quick Post Duplicator
(8c412c0666baee67ae3ee0f0eb18d8d95123aee2)
, Jun 07, 2024
|
WP Quick Post Duplicator
(CVE-2023-31214)
, Jun 10, 2024
|
Post Duplicator
, Dec 17, 2024
|
Post Duplicator
(CVE-2024-12472)
, Jan 12, 2025
|
New vulnerability |
The Ultimate WordPress Toolkit – WP Extended
(CVE-2024-13184)
, Jan 20, 2025
|
WP Abstracts
(CVE-2024-12385)
, Jan 20, 2025
|
Ad Blocking Detector
(CVE-2025-22732)
, Jan 19, 2025
|
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media
(CVE-2024-12071)
, Jan 19, 2025
|
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced)
(CVE-2025-22710)
, Jan 19, 2025
|