The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capability without checking whether the requesting user holds `publish_posts` or other status-gated capabilities. This makes it possible for authenticated attackers, with Contributor-level access and above, to create duplicate posts with `future` (scheduled, auto-publishes) or `private` status, bypassing editorial review. Additionally, the REST endpoint does not enforce administrator-configured post-type duplication restrictions, allowing duplication of post types that have been explicitly disabled.
History

Sat, 22 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Metaphorcreations
Metaphorcreations post Duplicator
Wordpress
Wordpress wordpress
Vendors & Products Metaphorcreations
Metaphorcreations post Duplicator
Wordpress
Wordpress wordpress

Sat, 22 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capability without checking whether the requesting user holds `publish_posts` or other status-gated capabilities. This makes it possible for authenticated attackers, with Contributor-level access and above, to create duplicate posts with `future` (scheduled, auto-publishes) or `private` status, bypassing editorial review. Additionally, the REST endpoint does not enforce administrator-configured post-type duplication restrictions, allowing duplication of post types that have been explicitly disabled.
Title Post Duplicator <= 3.0.11 - Authorization Bypass to Authenticated (Contributor+) Post Duplication
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-22T11:30:40.062Z

Reserved: 2026-03-15T21:44:14.805Z

Link: CVE-2026-4245

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T12:16:25.400

Modified: 2026-08-22T12:16:25.400

Link: CVE-2026-4245

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T14:00:17Z