Description
The WP Delete Post Copies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Published: 2025-11-21
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

The WP Delete Post Copies plugin contains insufficient input sanitisation and output escaping in its admin settings, allowing an authenticated user with administrator‑level permissions and higher to store arbitrary scripts. This results in a CWE‑79 type stored cross‑site scripting vulnerability. When a page containing the injected content is viewed, the script will execute in the context of the page. The vulnerability therefore provides a path for a stored cross‑site scripting attack that can compromise the integrity and confidentiality of user sessions. Based on the description, it is inferred that the script execution could be used to modify page contents or extract data from the visitor’s browser.

Affected Systems

The flaw affects WordPress installations that use WP Delete Post Copies by etruel, version 6.0.2 or earlier. It is limited to multi‑site deployments and only when the unfiltered_html capability has been disabled. Only users with administrator or higher privileges can exploit the weakness.

Risk and Exploitability

The CVSS score of 4.4 indicates a moderate severity level. The EPSS score of less than 1% suggests that overall exploitation probability is low, and the vulnerability is not listed in CISA’s KEV catalogue. Because the attack requires authenticated administrator access, the practical attack surface is constrained to sites where such privileged accounts exist. Once the payload is stored, any visitor to the affected page will receive the malicious script, allowing the attacker to affect a broad set of users if the page is widely accessed.

Generated by OpenCVE AI on April 22, 2026 at 16:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WP Delete Post Copies to version 6.0.3 or later, which resolves the insecure input handling.
  • If the plugin is not required for site functionality, delete or deactivate it to remove the attack surface.
  • Restrict the unfiltered_html capability to trusted administrators and ensure it is disabled on all non‑needed installations, thereby limiting the possibility of future stored XSS injections.

Generated by OpenCVE AI on April 22, 2026 at 16:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 21 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
Description The WP Delete Post Copies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Title WP Delete Post Copies <= 6.0.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:09:30.331Z

Reserved: 2025-10-22T13:16:05.990Z

Link: CVE-2025-12066

cve-icon Vulnrichment

Updated: 2025-11-21T14:53:37.950Z

cve-icon NVD

Status : Deferred

Published: 2025-11-21T10:15:46.710

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-12066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T16:45:21Z

Weaknesses