Authorization Flaw in WP Quick Post Duplicator by Arul Prasad J
CVE-2026-24387

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 January 2026

What is CVE-2026-24387?

A vulnerability in the WP Quick Post Duplicator plugin, developed by Arul Prasad J, allows attackers to exploit incorrectly configured access controls. This flaw could potentially enable unauthorized users to access restricted functionalities and data, thereby compromising the security of WordPress installations using version 2.1 or earlier. It is critical for users to review and implement proper access control measures to safeguard against this type of threat.

Affected Version(s)

WP Quick Post Duplicator <= n/a

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan | Patchstack Bug Bounty Program
.