Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Post Duplicator — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
post-duplicator
- 200000+ instalaciones activas
duplicateduplicationpostposts
Estado de mantenimiento
- Última versión conocida: 3.0.15
- Requiere PHP: 7.4+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
8 CVEs conocidos registrados para Post Duplicator.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-10749
|
Post Duplicator [post-duplicator] < 3.0.15 |
Deserialización de datos no confiables |
Desconocido
|
< 3.0.15
|
3.0.15 |
2026-06-24 |
✓ corregido en la última versión
|
|
CVE-2026-39474
|
Post Duplicator [post-duplicator] < 3.0.11 |
Deserialización de datos no confiables |
Alta
8,8
|
< 3.0.11
|
3.0.11 |
2026-04-13 |
✓ corregido en la última versión
|
|
CVE-2025-24736
|
Post Duplicator [post-duplicator] < 2.36 |
Falta de control de autorización |
Media
4,3
|
< 2.36
|
2.36 |
2025-01-24 |
✓ corregido en la última versión
|
|
CVE-2024-12472
|
Post Duplicator [post-duplicator] < 2.37 |
Elusión de autorización mediante una clave controlada por el usuario |
Media
4,3
|
< 2.37
|
2.37 |
2025-01-10 |
✓ corregido en la última versión
|
|
CVE-2023-49835
|
Post Duplicator [post-duplicator] < 2.32 |
Falta de control de autorización |
Media
4,3
|
< 2.32
|
2.32 |
2023-12-05 |
✓ corregido en la última versión
|
|
CVE-2016-15027
|
Post Duplicator [post-duplicator] < 2.19 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 2.19
|
2.19 |
2023-02-20 |
✓ corregido en la última versión
|
|
CVE-2021-33852
|
Post Duplicator [post-duplicator] < 2.27 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2.27
|
2.27 |
2021-12-02 |
✓ corregido en la última versión
|
|
—
|
Post Duplicator [post-duplicator] < 2.17 |
— |
Desconocido
|
< 2.17
|
2.17 |
2016-04-06 |
✓ corregido en la última versión
|
CVE-2026-10749
The Post Duplicator plugin for WordPress is vulnerable to PHP Object Injection in versions up to 3.0.15 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-39474
The Post Duplicator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.10 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-24736
The Post Duplicator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-12472
The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to by duplicating the post.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-49835
Update the WordPress Post Duplicator plugin to the latest available version (at least 2.32).
Huynh Tien Si discovered and reported this Broken Access Control vulnerability in WordPress Post Duplicator Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 2.32.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2016-15027
A vulnerability was found in meta4creations Post Duplicator Plugin 2.18 on WordPress. It has been classified as problematic. Affected is the function mtphr_post_duplicator_notice of the file includes/notices.php. The manipulation of the argument post-duplicated leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.19 is able to address this issue. The name of the patch is ca67c05e490c0cf93a1e9b2d93bfeff3dd96f594. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-221496.
[de] Es wurde eine problematische Schwachstelle in meta4creations Post Duplicator Plugin 2.18 für WordPress ausgemacht. Hiervon betroffen ist die Funktion mtphr_post_duplicator_notice der Datei includes/notices.php. Dank der Manipulation des Arguments post-duplicated mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Ein Aktualisieren auf die Version 2.19 vermag dieses Problem zu lösen. Der Patch wird als ca67c05e490c0cf93a1e9b2d93bfeff3dd96f594 bezeichnet. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2021-33852
A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box executes whenever the user opens the Settings Page of the Post Duplicator Plugin or the application root page after duplicating any of the existing posts.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Post Duplicator [post-duplicator] < 2.17
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Upgrade the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
+ 3 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
—
|
Post Duplicator [post-duplicator] < 2.17 |
— |
Desconocido
|
< 2.17
|
2.17 |
2016-04-06 |
✓ corregido en la última versión
|
|
CVE-2026-2301
|
Post Duplicator [post-duplicator] < 3.0.9 |
— |
Desconocido
|
< 3.0.9
|
3.0.9 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Post Duplicator [post-duplicator] < 2.17 |
— |
Desconocido
|
< 2.17
|
2.17 |
— |
✓ corregido en la última versión
|
Post Duplicator [post-duplicator] < 2.17
The Post Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.16 due to insufficient input sanitization and output escaping on the 'post-duplicated' parameter. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-2301
The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all versions up to, and including, 3.0.8. This is due to the `duplicate_post()` function in `includes/api.php` using `$wpdb->insert()` directly to the `wp_postmeta` table instead of WordPress's standard `add_post_meta()` function, which would call `is_protected_meta()` to prevent lower-privileged users from setting protected meta keys (those starting with `_`). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary protected post meta keys such as `_wp_page_template`, `_wp_attached_file`, and other sensitive meta keys on duplicated posts via the `customMetaData` JSON array parameter in the `/wp-json/post-duplicator/v1/duplicate-post` REST API endpoint.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Post Duplicator [post-duplicator] < 2.17
The Post Duplicator WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Cómo solucionarlo
Mantén Post Duplicator actualizado — 3.0.15 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas