The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 21 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Fri, 21 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable. | |
| Title | Copy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-21T06:00:17.169Z
Reserved: 2026-08-06T12:20:24.301Z
Link: CVE-2026-19085
No data.
Status : Received
Published: 2026-08-21T07:16:25.243
Modified: 2026-08-21T07:16:25.243
Link: CVE-2026-19085
No data.
OpenCVE Enrichment
Updated: 2026-08-21T07:45:03Z
Weaknesses