| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-2301 | Post Duplicator <= 3.0.8 - Missing Authorization to Authenticated (Contributor+) Protected Post Meta Insertion via 'customMetaData' Parameter | metaphorcreations | Post Duplicator | Medium | 4.3 | 2026-02-25 09:26:51 | Deep Dive |
| CVE-2025-60105 | WordPress Ditty Plugin <= 3.1.58 - Cross Site Scripting (XSS) Vulnerability | metaphorcreations | Ditty | Medium | 6.5 | 2025-09-26 08:31:25 | Deep Dive |
| CVE-2025-24736 | WordPress Post Duplicator plugin <= 2.35 - Broken Access Control vulnerability | metaphorcreations | Post Duplicator | Medium | 4.3 | 2025-01-24 17:25:24 | Deep Dive |
| CVE-2025-23816 | WordPress Metaphor Widgets plugin <= 2.4 - Stored Cross Site Scripting (XSS) vulnerability | metaphorcreations | Metaphor Widgets | Medium | 6.5 | 2025-01-16 20:08:16 | Deep Dive |
| CVE-2024-12472 | Post Duplicator <= 2.36 - Authenticated (Contributor+) Protected Post Disclosure | metaphorcreations | Post Duplicator | Medium | 4.3 | 2025-01-11 02:20:54 | Deep Dive |
| CVE-2023-47764 | WordPress Ditty plugin <= 3.1.24 - Broken Access Control vulnerability | metaphorcreations | Ditty | 中危 | - | 2024-12-09 11:30:48 | Deep Dive |
| CVE-2023-49835 | WordPress Post Duplicator plugin <= 2.31 - Broken Access Control vulnerability | metaphorcreations | Post Duplicator | Medium | 4.3 | 2024-12-09 11:30:07 | Deep Dive |
| CVE-2024-3954 | Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.38 - Authenticated (Contributor+) PHP Object Injection | metaphorcreations | Ditty – Responsive News Tickers, Sliders, and Lists | High | 8.8 | 2024-05-09 20:03:20 | Deep Dive |