Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19077— Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization

AI Predicted 6.5 Difficulty: Easy EPSS 0.13% · P3
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-19077

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization
Source: CVE Program / CVE List V5
Vulnerability Description
The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
UnknownDuplicate Post 0 ~ 1.5.5 -

II. Public POCs for CVE-2026-19077

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19077

登录查看更多情报信息。

Vendor Advisories for CVE-2026-19077 (1)

Same Patch Batch · Unknown · 2026-08-10 · 48 CVEs total

CVE-2026-17010Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta
CVE-2026-16299Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset
CVE-2026-18468Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verif
CVE-2026-16298FoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset
CVE-2026-18030Bricksforge < 3.1.8.8 - Unauthenticated Arbitrary Password Reset via Pro Forms
CVE-2026-17541Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure
CVE-2026-17542Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector
CVE-2026-17540Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Comm
CVE-2026-16257Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret T
CVE-2026-17016Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment
CVE-2026-17012Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver
CVE-2026-18666Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value
CVE-2026-17018CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR
CVE-2026-12971LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_featur
CVE-2026-13600AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron
CVE-2026-13170Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting
CVE-2026-13701Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting
CVE-2026-14206HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure
CVE-2026-14860Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery
CVE-2026-14941Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multipl

Showing top 20 of 48 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-19077

No comments yet


Leave a comment