Impact
The Duplicate Post plugin contains a stored cross‑site scripting flaw that arises from inadequate sanitization of the 'noti_token' parameter. An attacker who can assume a subscriber-level or higher authenticated role on the WordPress site can introduce arbitrary script content into notification pages. When any user views the affected page, the injected script executes in their browser, allowing client‑side code injection, phishing, session hijacking or data exfiltration that can compromise the confidentiality and integrity of user sessions.
Affected Systems
All installations of the Duplicate Post WordPress plugin produced by vendor inisev, version 1.5.6 and earlier, are vulnerable. The issue resides in the plugin’s notification handling code, specifically the AJAX branch accessed by users with the Subscriber role when the plugin’s User Level Permissions feature is enabled.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4, which reflects a moderate severity but indicates that successful exploitation can pose a real risk to users. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been actively leveraged in widespread attacks. However, the requirement of authenticated subscription-level access means that any user who can reach the notification pages with sufficient privileges could install and run malicious scripts. The principal vector is an authenticated web request, making it important to limit user permissions or update the plugin to eliminate the flaw.
OpenCVE Enrichment