Description
The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplication due to a missing capability check on the duplicate_ppmc_post_as_draft function in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers with subscriber access or higher to duplicate posts and pages.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54636 | The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplication due to a missing capability check on the duplicate_ppmc_post_as_draft function in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers with subscriber access or higher to duplicate posts and pages. |
References
History
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Duplicate Post Page Menu & Custom Post Type <= 2.3.1 - Missing Authorization to Post Duplication | |
| Weaknesses | CWE-862 |
Wed, 05 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:26:26.248Z
Reserved: 2023-09-06T12:47:07.323Z
Link: CVE-2023-4792
Updated: 2024-08-02T07:38:00.521Z
Status : Modified
Published: 2023-09-07T02:15:08.163
Modified: 2026-04-08T19:18:35.090
Link: CVE-2023-4792
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD