Impact
An attacker who can provide input to the Duplicate Page and Post plugin can store malicious scripts that will be rendered when the affected page or post is displayed. This stored cross‑site scripting flaw allows the attacker to execute arbitrary scripts in users’ browsers, enabling cookie theft, session hijacking, or defacement of the site content.
Affected Systems
The vulnerability affects all installations of Falcon Solutions Duplicate Page and Post plugin version 1.0 or earlier. The plugin’s development version is not known to be affected, but explicit support is limited to the stated vintage range.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity vulnerability. With an EPSS score below 1% and no listing in the CISA KEV catalog, the likelihood of exploitation at time of analysis is low. The likely attack vector is through the plugin’s administrative interface or data entry points that store user‑supplied content, which then propagates to front‑end pages accessible to visitors.
OpenCVE Enrichment
EUVD