Impact
The Duplicate Post WordPress plugin prior to version 1.5.5 contains a flaw in its bulk copy and delete functions that fails to perform per‑object authorization checks. As a result, any authenticated user who has been granted plugin access by a site administrator can request the deletion of any post on the site, regardless of ownership. This flaw is an instance of Authorization Bypass (CWE‑639). The ability to permanently delete posts permits complete data loss for content created by other users, jeopardizing the integrity and availability of the site's content.
Affected Systems
WordPress sites running the Duplicate Post plugin at any version older than 1.5.5 are vulnerable. The vulnerability applies to any user who has permission to use bulk copy or delete within the plugin, which administrators typically grant to editors or other privileged roles.
Risk and Exploitability
The flaw requires an authenticated session and the user must have been given access to the plugin’s bulk features, which limits the attacker to users already trusted by an administrator. The CVSS score of 6.5 indicates moderate severity, and the EPSS score of <1% indicates a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the impact of permanent post deletion is significant. An attacker could cause irreversible loss of content and disrupt site operations if the plugin is enabled for overly broad user roles.
OpenCVE Enrichment