Impact
The Duplicate Post WordPress plugin fails to verify that a user is authorized to view a post before duplicating it. This oversight allows any user with a delegated role to duplicate another user’s password‑protected post and republish it as publicly readable, thereby exposing content that was intended to remain private. The primary impact is the compromise of confidentiality, potentially revealing sensitive or private information to unauthorized parties.
Affected Systems
Any WordPress installation that has the Duplicate Post plugin installed and running a version earlier than 1.5.6 is vulnerable. The plugin’s name is "Duplicate Post" and is used for creating copies of posts. Users who are assigned delegated roles such as editor or author can trigger the duplication action. No specific vendor is listed, but the product is the Duplicate Post plugin for WordPress. The version indicator is "before 1.5.6".
Risk and Exploitability
Because no CVSS score or EPSS probability is provided, the absolute severity can only be inferred from the description. The vulnerability can be exploited by any user who possesses a delegated role that has access to the duplicate function; it does not require any special network exposure or local privileges. Although the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, the ability to leak protected content represents a significant threat to confidentiality. The risk is high for installations that allow delegated roles to duplicate posts, especially when those roles are broadly granted. Direct exploitation appears straightforward, relying on a normal plugin feature rather than an advanced attack chain. Consequently, organizations should treat this finding as high‑priority remediation.
OpenCVE Enrichment