Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-4245— Post Duplicator <= 3.0.11 - Authorization Bypass to Authenticated (Contributor+) Post Duplication

Quick assessment

Affected
metaphorcreations Post Duplicator
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Post Duplicator 插件在所有 3.0.11 及更早版本中存在授权绕过漏洞。该漏洞源于 权限回调仅验证了用户是否具备 能力,而未检查请求用户是否拥有 或其他基于状态限制的能力。这使得拥有贡献者(Contributor)及以上权限的认证攻击者能够创建具有“未来(future,即预定时自动发布)”或“私有(private)”状态的重复文章,从而绕过编辑审核流程。此外,REST 端点未强制执行管理员配置的特定文章类型复制限制,允许复制已被明确禁用的文章类型。

CVSS 4.3 · Medium EPSS 0.29% · P21

Affected Version Matrix 1

VendorProduct Version RangeStatus
metaphorcreations Post Duplicator ≤ 3.0.11 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-4245

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Post Duplicator <= 3.0.11 - Authorization Bypass to Authenticated (Contributor+) Post Duplication
Source: CVE Program / CVE List V5
Vulnerability Description
The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capability without checking whether the requesting user holds `publish_posts` or other status-gated capabilities. This makes it possible for authenticated attackers, with Contributor-level access and above, to create duplicate posts with `future` (scheduled, auto-publishes) or `private` status, bypassing editorial review. Additionally, the REST endpoint does not enforce administrator-configured post-type duplication restrictions, allowing duplication of post types that have been explicitly disabled.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
metaphorcreations Post Duplicator 0 ~ 3.0.11 -

II. Public POCs for CVE-2026-4245

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-4245

登录查看更多情报信息。

News Coverage for CVE-2026-4245 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-4245

No comments yet


Leave a comment