Security Flaw in Post Duplicator Plugin for WordPress
CVE-2026-10749
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 24 June 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-10749?
The Post Duplicator WordPress plugin, prior to version 3.0.15, exhibits a security flaw that inadequately manages custom meta-data during post duplication processes. This oversight allows an attacker with Contributor-level access or higher to inject serialized PHP objects. By bypassing the WordPress meta API's double-serialization protection, unauthorized modifications can be made, posing significant risks to the site's security and integrity.
Affected Version(s)
Post Duplicator 0 < 3.0.15
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.