WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Post Duplicator?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Post Duplicator — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: post-duplicator
  • 200000+ instalaciones activas

duplicateduplicationpostposts

Estado de mantenimiento

  • Última versión conocida: 3.0.15
  • Requiere PHP: 7.4+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

8 CVEs conocidos registrados para Post Duplicator.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-10749 Post Duplicator [post-duplicator] < 3.0.15 Deserialización de datos no confiables Desconocido < 3.0.15 3.0.15 2026-06-24 ✓ corregido en la última versión
CVE-2026-39474 Post Duplicator [post-duplicator] < 3.0.11 Deserialización de datos no confiables Alta 8,8 < 3.0.11 3.0.11 2026-04-13 ✓ corregido en la última versión
CVE-2025-24736 Post Duplicator [post-duplicator] < 2.36 Falta de control de autorización Media 4,3 < 2.36 2.36 2025-01-24 ✓ corregido en la última versión
CVE-2024-12472 Post Duplicator [post-duplicator] < 2.37 Elusión de autorización mediante una clave controlada por el usuario Media 4,3 < 2.37 2.37 2025-01-10 ✓ corregido en la última versión
CVE-2023-49835 Post Duplicator [post-duplicator] < 2.32 Falta de control de autorización Media 4,3 < 2.32 2.32 2023-12-05 ✓ corregido en la última versión
CVE-2016-15027 Post Duplicator [post-duplicator] < 2.19 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 2.19 2.19 2023-02-20 ✓ corregido en la última versión
CVE-2021-33852 Post Duplicator [post-duplicator] < 2.27 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 2.27 2.27 2021-12-02 ✓ corregido en la última versión
Post Duplicator [post-duplicator] < 2.17 Desconocido < 2.17 2.17 2016-04-06 ✓ corregido en la última versión

CVE-2026-10749

The Post Duplicator plugin for WordPress is vulnerable to PHP Object Injection in versions up to 3.0.15 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-39474

The Post Duplicator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.10 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-24736

The Post Duplicator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-12472

The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to by duplicating the post.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-49835

Update the WordPress Post Duplicator plugin to the latest available version (at least 2.32). Huynh Tien Si discovered and reported this Broken Access Control vulnerability in WordPress Post Duplicator Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 2.32.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2016-15027

A vulnerability was found in meta4creations Post Duplicator Plugin 2.18 on WordPress. It has been classified as problematic. Affected is the function mtphr_post_duplicator_notice of the file includes/notices.php. The manipulation of the argument post-duplicated leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.19 is able to address this issue. The name of the patch is ca67c05e490c0cf93a1e9b2d93bfeff3dd96f594. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-221496. [de] Es wurde eine problematische Schwachstelle in meta4creations Post Duplicator Plugin 2.18 für WordPress ausgemacht. Hiervon betroffen ist die Funktion mtphr_post_duplicator_notice der Datei includes/notices.php. Dank der Manipulation des Arguments post-duplicated mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Ein Aktualisieren auf die Version 2.19 vermag dieses Problem zu lösen. Der Patch wird als ca67c05e490c0cf93a1e9b2d93bfeff3dd96f594 bezeichnet. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-33852

A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box executes whenever the user opens the Settings Page of the Post Duplicator Plugin or the application root page after duplicating any of the existing posts.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Post Duplicator [post-duplicator] < 2.17

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Upgrade the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

+ 3 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
Post Duplicator [post-duplicator] < 2.17 Desconocido < 2.17 2.17 2016-04-06 ✓ corregido en la última versión
CVE-2026-2301 Post Duplicator [post-duplicator] < 3.0.9 Desconocido < 3.0.9 3.0.9 0000-00-00 ✓ corregido en la última versión
Post Duplicator [post-duplicator] < 2.17 Desconocido < 2.17 2.17 ✓ corregido en la última versión

Post Duplicator [post-duplicator] < 2.17

The Post Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.16 due to insufficient input sanitization and output escaping on the 'post-duplicated' parameter. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-2301

The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all versions up to, and including, 3.0.8. This is due to the `duplicate_post()` function in `includes/api.php` using `$wpdb->insert()` directly to the `wp_postmeta` table instead of WordPress's standard `add_post_meta()` function, which would call `is_protected_meta()` to prevent lower-privileged users from setting protected meta keys (those starting with `_`). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary protected post meta keys such as `_wp_page_template`, `_wp_attached_file`, and other sensitive meta keys on duplicated posts via the `customMetaData` JSON array parameter in the `/wp-json/post-duplicator/v1/duplicate-post` REST API endpoint.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Post Duplicator [post-duplicator] < 2.17

The Post Duplicator WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Post Duplicator actualizado — 3.0.15 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.