Description
The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable.
Published:
2026-08-21
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 21 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable. | |
| Title | Copy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-21T06:00:17.169Z
Reserved: 2026-08-06T12:20:24.301Z
Link: CVE-2026-19085
No data.
Status : Received
Published: 2026-08-21T07:16:25.243
Modified: 2026-08-21T07:16:25.243
Link: CVE-2026-19085
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.