Impact
The Duplicate Post WordPress plugin fails to verify that a user is authorized to view a post before duplicating it. This oversight allows any user with a delegated role to duplicate another user’s password‑protected post and republish it as publicly readable, thereby exposing content that was intended to remain private. The primary impact is the compromise of confidentiality, potentially revealing sensitive or private information to unauthorized parties.
Affected Systems
Any WordPress installation that has the Duplicate Post plugin installed and running a version earlier than 1.5.6 is vulnerable. The plugin’s name is "Duplicate Post" and is used for creating copies of posts. Users who are assigned delegated roles such as editor or author can trigger the duplication action. No specific vendor is listed, but the product is the Duplicate Post plugin for WordPress. The version indicator is "before 1.5.6".
Risk and Exploitability
With a CVSS score of 2.7 and an EPSS probability of less than 1%, the absolute severity of this vulnerability is low. Exploitation requires an authenticated user who has permission to use the duplication feature in the plugin, allowing them to copy a password‑protected post and republish it as publicly readable. This results in a confidentiality breach of the protected content. The vulnerability is not listed in CISA KEV and no special conditions beyond role permissions are described in the advisory. The risk is relatively low for installations that restrict duplication permissions, but any deployment that grants those permissions broadly remains vulnerable.
OpenCVE Enrichment