CVE · Medium

CVE-2025-24736 — Post Duplicator [post-duplicator] < 2.36

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-24736 Post Duplicator [post-duplicator] < 2.36 Missing Authorization Medium 4.3 < 2.36 2.36 2025-01-24

CVE-2025-24736

A security flaw exists within the Post Duplicator plugin for WordPress, where a critical oversight has been identified in its authorization mechanism. Specifically, a capability check is absent from a function across all versions up to 2.35, allowing users with Contributor-level access or higher to execute an unauthorized operation without proper clearance.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.