Description
Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Kumar WP Bulk Post Duplicator wp-bulk-post-duplicator allows Cross Site Request Forgery.This issue affects WP Bulk Post Duplicator: from n/a through <= 1.2.
Published: 2025-03-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Bulk Post Duplicator plugin for WordPress versions up to and including 1.2 implements no Cross‑Site Request Forgery protection for its duplicate post function. A malicious actor can send a crafted request to a site where an authorized administrator is logged in, forcing the duplicate action and creating unintended copies of existing posts. The effect is an unauthorized change of content, potential site clutter, performance degradation, and, in worst cases, data integrity compromise if the duplicated content is incorrectly edited or contains malicious data.

Affected Systems

This vulnerability affects WordPress sites that have installed the Rajesh Kumar WP Bulk Post Duplicator plugin version 1.2 or earlier. Any site that relies on this plugin for bulk post duplication is at risk, regardless of other security measures in place.

Risk and Exploitability

The vulnerability carries a CVSS score of 4.3, indicating a moderate risk level. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the issue is not listed in the CISA KEV catalog. Attackers would need to target a WordPress site where an administrator with an active session is present; the vector would be an HTTP request to the duplicate endpoint, often via a social‑engineering link or embedded image. Without the need for additional authentication privileges, the attack can succeed if the targeted admin is tricked into visiting a malicious URL.

Generated by OpenCVE AI on May 1, 2026 at 14:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Bulk Post Duplicator plugin to a version newer than 1.2 or uninstall the plugin if it is not required.
  • Apply the latest WordPress core updates and enforce strong administrative authentication, including two‑factor authentication.
  • Limit administrative access to trusted IP addresses or network segments to reduce the chance of a CSRF request affecting an active session.
  • If an immediate upgrade is not possible, temporarily disable the duplicate functionality or add a custom nonce check to the action as a workaround until a vendor patch is released.

Generated by OpenCVE AI on May 1, 2026 at 14:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7848 Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Kumar WP Bulk Post Duplicator allows Cross Site Request Forgery. This issue affects WP Bulk Post Duplicator: from n/a through 1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Kumar WP Bulk Post Duplicator allows Cross Site Request Forgery. This issue affects WP Bulk Post Duplicator: from n/a through 1.2. Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Kumar WP Bulk Post Duplicator wp-bulk-post-duplicator allows Cross Site Request Forgery.This issue affects WP Bulk Post Duplicator: from n/a through <= 1.2.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00021}

epss

{'score': 0.00029}


Wed, 12 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Kumar WP Bulk Post Duplicator allows Cross Site Request Forgery. This issue affects WP Bulk Post Duplicator: from n/a through 1.2.
Title WordPress WP Bulk Post Duplicator plugin <= 1.2 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:49.883Z

Reserved: 2025-03-11T08:09:00.484Z

Link: CVE-2025-28884

cve-icon Vulnrichment

Updated: 2025-03-12T13:45:14.662Z

cve-icon NVD

Status : Deferred

Published: 2025-03-11T21:15:45.960

Modified: 2026-04-23T15:26:30.247

Link: CVE-2025-28884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:15:20Z

Weaknesses