| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-2301 | Post Duplicator <= 3.0.8 - Missing Authorization to Authenticated (Contributor+) Protected Post Meta Insertion via 'customMetaData' Parameter | metaphorcreations | Post Duplicator | Medium | 4.3 | 2026-02-25 09:26:51 | Deep Dive |
| CVE-2026-1104 | FastDup – Fastest WordPress Migration & Duplicator <= 2.7.1 - Missing Authorization to Authenticated (Contributor+) Backup Creation and Download | ninjateam | FastDup – Fastest WordPress Migration & Duplicator | High | 8.8 | 2026-02-12 14:25:41 | Deep Dive |
| CVE-2026-24387 | WordPress WP Quick Post Duplicator plugin <= 2.1 - Broken Access Control vulnerability | Arul Prasad J | WP Quick Post Duplicator | Medium | 4.3 | 2026-01-22 16:52:48 | Deep Dive |
| CVE-2026-0604 | FastDup <= 2.7 - Authenticated (Contributor+) Path Traversal via 'dir_path' REST Parameter | ninjateam | FastDup – Fastest WordPress Migration & Duplicator | Medium | 6.5 | 2026-01-06 03:21:39 | Deep Dive |
| CVE-2025-52760 | WordPress MultiSite Clone Duplicator plugin <= 1.5.3 - Cross Site Scripting (XSS) vulnerability | Globalis | MultiSite Clone Duplicator | High | 7.1 | 2025-10-22 14:32:28 | Deep Dive |
| CVE-2025-27282 | WordPress Theme File Duplicator Plugin <= 1.3 - Arbitrary File Upload vulnerability | rockgod100 | Theme File Duplicator | Critical | 9.9 | 2025-04-17 15:48:11 | Deep Dive |
| CVE-2025-27283 | WordPress Theme File Duplicator Plugin <= 1.3 - Arbitrary File Download vulnerability | rockgod100 | Theme File Duplicator | Medium | 6.5 | 2025-04-17 15:48:10 | Deep Dive |
| CVE-2025-32567 | WordPress Easy Post Duplicator Plugin <= 1.0.1 - SQL Injection vulnerability | dev02ali | Easy Post Duplicator | High | 8.5 | 2025-04-11 08:42:57 | Deep Dive |
| CVE-2025-32538 | WordPress Easy Post Duplicator Plugin <= 1.0.1 - Reflected Cross Site Scripting (XSS) vulnerability | dev02ali | Easy Post Duplicator | High | 7.1 | 2025-04-11 08:42:55 | Deep Dive |
| CVE-2025-31845 | WordPress Theme Duplicator Plugin <= 1.1 - Cross Site Request Forgery (CSRF) vulnerability | Rohit Choudhary | Theme Duplicator | Medium | 4.3 | 2025-04-01 14:51:57 | Deep Dive |
| CVE-2025-31809 | WordPress Labinator Content Types Duplicator Plugin <= 1.1.3 - Cross Site Request Forgery (CSRF) vulnerability | Labinator | Labinator Content Types Duplicator | Medium | 4.3 | 2025-04-01 14:51:39 | Deep Dive |
| CVE-2025-30543 | WordPress Menu Duplicator plugin <= 1.0 - Broken Access Control vulnerability | swayam.tejwani | Menu Duplicator | Medium | 4.3 | 2025-03-24 13:46:51 | Deep Dive |
| CVE-2025-28884 | WordPress WP Bulk Post Duplicator plugin <= 1.2 - Cross Site Request Forgery (CSRF) vulnerability | Rajesh Kumar | WP Bulk Post Duplicator | Medium | 4.3 | 2025-03-11 21:00:45 | Deep Dive |
| CVE-2025-24736 | WordPress Post Duplicator plugin <= 2.35 - Broken Access Control vulnerability | metaphorcreations | Post Duplicator | Medium | 4.3 | 2025-01-24 17:25:24 | Deep Dive |
| CVE-2024-12472 | Post Duplicator <= 2.36 - Authenticated (Contributor+) Protected Post Disclosure | metaphorcreations | Post Duplicator | Medium | 4.3 | 2025-01-11 02:20:54 | Deep Dive |
| CVE-2023-31214 | WordPress WP Quick Post Duplicator plugin <= 2.0 - Broken Access Control vulnerability | Arul Prasad J | WP Quick Post Duplicator | Medium | 5.4 | 2024-12-09 11:30:59 | Deep Dive |
| CVE-2023-49835 | WordPress Post Duplicator plugin <= 2.31 - Broken Access Control vulnerability | metaphorcreations | Post Duplicator | Medium | 4.3 | 2024-12-09 11:30:07 | Deep Dive |
| CVE-2024-6210 | Duplicator <= 1.5.9 - Full Path Disclosure | smub | Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More | Medium | 5.3 | 2024-07-11 02:03:49 | Deep Dive |
| CVE-2023-51681 | WordPress Duplicator Plugin <= 1.5.7 is vulnerable to Cross Site Request Forgery (CSRF) | Duplicator | Duplicator – WordPress Migration & Backup Plugin | Medium | 6.5 | 2024-02-28 16:41:37 | Deep Dive |
| CVE-2024-1368 | Page Duplicator <= 0.1.1 - Missing Authorization to Unauthenticated Post/Page Duplication | samuelkwle | Page Duplicator | Medium | 5.3 | 2024-02-28 08:33:12 | Deep Dive |