CVE · Medium

CVE-2024-12472 — Post Duplicator [post-duplicator] < 2.37

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-12472 Post Duplicator [post-duplicator] < 2.37 Authorization Bypass Through User-Controlled Key Medium 4.3 < 2.37 2.37 2025-01-10

CVE-2024-12472

The Post Duplicator plugin for WordPress contains an information disclosure flaw in versions 2.36 and earlier within the mtphr_duplicate_post() function that fails to properly validate post access permissions. Users with Contributor-level permissions or higher can duplicate posts they lack authorization to view, including those marked as password protected, private, or in draft status, thereby gaining unauthorized access to restricted content.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.