The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users.
History

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Duplicate Post Project
Duplicate Post Project duplicate Post
Wordpress
Wordpress wordpress
Vendors & Products Duplicate Post Project
Duplicate Post Project duplicate Post
Wordpress
Wordpress wordpress

Mon, 10 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users.
Title Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-10T06:00:20.031Z

Updated: 2026-08-11T20:57:20.495Z

Reserved: 2026-08-06T10:36:45.337Z

Link: CVE-2026-19077

cve-icon Vulnrichment

Updated: 2026-08-11T20:57:13.483Z

cve-icon NVD

Status : Received

Published: 2026-08-10T07:16:51.377

Modified: 2026-08-11T21:17:34.927

Link: CVE-2026-19077

cve-icon Redhat

No data.