Description
The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin's User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload.
Published: 2026-10-01
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Patch
AI Analysis

Impact

The Duplicate Post plugin contains a stored cross‑site scripting flaw that arises from inadequate sanitization of the 'noti_token' parameter. An attacker who can assume a subscriber-level or higher authenticated role on the WordPress site can introduce arbitrary script content into notification pages. When any user views the affected page, the injected script executes in their browser, allowing client‑side code injection, phishing, session hijacking or data exfiltration that can compromise the confidentiality and integrity of user sessions.

Affected Systems

All installations of the Duplicate Post WordPress plugin produced by vendor inisev, version 1.5.6 and earlier, are vulnerable. The issue resides in the plugin’s notification handling code, specifically the AJAX branch accessed by users with the Subscriber role when the plugin’s User Level Permissions feature is enabled.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.4, which reflects a moderate severity but indicates that successful exploitation can pose a real risk to users. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been actively leveraged in widespread attacks. However, the requirement of authenticated subscription-level access means that any user who can reach the notification pages with sufficient privileges could install and run malicious scripts. The principal vector is an authenticated web request, making it important to limit user permissions or update the plugin to eliminate the flaw.

Generated by OpenCVE AI on October 1, 2026 at 11:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Duplicate Post plugin to version 1.5.7 or newer where the issue has been patched.
  • If an upgrade is not immediately possible, disable the plugin’s User Level Permissions for the Subscriber role or otherwise remove subscriber‑level access to the i_saw_this_noti AJAX branch to block the execution path used for the exploit.
  • Remove or sanitize the 'noti_token' parameter in the notification URLs or apply a custom patch that properly escapes output before rendering to prevent script injection.
  • Employ a security plugin or WAF rule that filters or blocks known XSS payloads to mitigate risk while remediation steps are pending.

Generated by OpenCVE AI on October 1, 2026 at 11:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin's User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload.
Title Duplicate Post <= 1.5.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'noti_token' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T14:13:50.290Z

Reserved: 2026-09-11T18:30:36.215Z

Link: CVE-2026-89424

cve-icon Vulnrichment

Updated: 2026-10-01T14:13:47.264Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T09:17:09.570

Modified: 2026-10-01T15:17:32.800

Link: CVE-2026-89424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T11:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')