Description
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content.
Published: 2026-03-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Post Duplication & Overwrite
Action: Update Plugin
AI Analysis

Impact

The Yoast Duplicate Post plugin for WordPress contains missing capability checks in the clone_bulk_action_handler() and republish_request() functions in all versions up to and including 4.5. The flaw, identified as CWE-862 (Missing Authorization), allows authenticated users with Contributor-level access or higher to duplicate any post—private, draft, or trashed—without restriction. Users with Author-level permissions can additionally use the Rewrite & Republish feature to overwrite any published post with their own content. This grants the attacker the ability to alter site content, potentially compromising the integrity and confidentiality of posts hosted on the site.

Affected Systems

Any WordPress installation that has the Yoast Duplicate Post plugin installed at version 4.5 or earlier is affected. The plugin is developed by Yoast and is distributed through the WordPress plugin repository. Sites running newer versions of the plugin are not affected.

Risk and Exploitability

The vulnerability has a CVSS score of 5.4, placing it in the moderate risk range. No EPSS score is available, so the real‑world likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The attack vector requires authentication; an attacker must log into the site and possess at least Contributor-level access to duplicate a post, and at least Author-level access to overwrite a post. Once authenticated, the missing authorization check allows the attacker to perform the actions without further approval.

Generated by OpenCVE AI on March 18, 2026 at 10:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Yoast Duplicate Post to the latest version that addresses this issue (any version newer than 4.5).
  • If an upgrade cannot be performed immediately, disable or uninstall the Yoast Duplicate Post plugin to eliminate the attack surface.

Generated by OpenCVE AI on March 18, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-g9w4-m5fx-x3wv Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
History

Wed, 18 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Yoast
Yoast yoast Duplicate Post
Vendors & Products Wordpress
Wordpress wordpress
Yoast
Yoast yoast Duplicate Post

Wed, 18 Mar 2026 09:45:00 +0000

Type Values Removed Values Added
Description The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content.
Title Yoast Duplicate Post <= 4.5 - Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Yoast Yoast Duplicate Post
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:33:31.708Z

Reserved: 2026-01-19T22:11:13.075Z

Link: CVE-2026-1217

cve-icon Vulnrichment

Updated: 2026-03-18T14:23:15.499Z

cve-icon NVD

Status : Deferred

Published: 2026-03-18T10:16:23.960

Modified: 2026-04-22T21:32:08.360

Link: CVE-2026-1217

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-24T10:59:03Z

Weaknesses