๐Ÿ” CVE Alert

CVE-2026-10749

UNKNOWN 0.0

Post Duplicator < 3.0.15 - Contributor+ PHP Object Injection via customMetaData

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, storing attacker-supplied serialized values without the WordPress meta API's double-serialization protection, allowing users with Contributor-level access and above to inject a PHP Object.

Vendor unknown
Product post duplicator
Published Jun 24, 2026
Stay Ahead of the Next One

Get instant alerts for unknown post duplicator

Be the first to know when new unknown vulnerabilities affecting unknown post duplicator are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Post Duplicator
0 < 3.0.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/224c36b5-e604-4eb3-aad8-47283b95e994/

Credits

Md. Minaruzzaman Shovon WPScan