CVE-2023-49835
The Post Duplicator plugin versions prior to 2.32 contain a broken access control vulnerability that allows unauthenticated or unprivileged users to perform actions reserved for higher-privileged roles due to missing authorization and nonce token validation. An attacker could exploit this flaw to execute restricted functionality without proper authentication checks. The vulnerability has been patched in version 2.32 and users should update their installations immediately.
Based on public CVE data (MITRE/NVD).