CVE-2026-19435
Copy & Delete Posts < 1.5.6 - Authenticated Arbitrary Post Content and Password Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content.
| Vendor | unknown |
| Product | duplicate post |
| Published | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown duplicate post
Be the first to know when new unknown vulnerabilities affecting unknown duplicate post are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Duplicate Post
0 < 1.5.6
References
Credits
Erwan LR (WPScan) WPScan