CVE Database /
CVE-2024-12472
CVE · Medium
CVE-2024-12472 — Post Duplicator [post-duplicator] < 2.37
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-12472
|
Post Duplicator [post-duplicator] < 2.37 |
Authorization Bypass Through User-Controlled Key |
Medium
4.3
|
< 2.37
|
2.37 |
2025-01-10 |
—
|
CVE-2024-12472
The Post Duplicator plugin for WordPress contains an information disclosure flaw in versions 2.36 and earlier within the mtphr_duplicate_post() function that fails to properly validate post access permissions. Users with Contributor-level permissions or higher can duplicate posts they lack authorization to view, including those marked as password protected, private, or in draft status, thereby gaining unauthorized access to restricted content.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings