Unauthorized Data Modification in Post Duplicator Plugin for WordPress
CVE-2026-4244
4.3MEDIUM
What is CVE-2026-4244?
The Post Duplicator plugin for WordPress contains a security flaw that allows authenticated users, including those with Contributor-level access, to duplicate posts associated with any user, without verifying their permissions. This occurs due to the lack of capability validation in the 'duplicate_post()' function when processing requests through the 'duplicate-post' REST endpoint. Consequently, this vulnerability poses a risk of unauthorized data manipulation, enabling potential abuse by attackers.
Affected Version(s)
Post Duplicator 0 <= 3.0.11