CVE Database /
CVE-2026-39474
CVE · High
CVE-2026-39474 — Post Duplicator [post-duplicator] < 3.0.11
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-39474
|
Post Duplicator [post-duplicator] < 3.0.11 |
Deserialization of Untrusted Data |
High
8.8
|
< 3.0.11
|
3.0.11 |
2026-04-13 |
—
|
CVE-2026-39474
A vulnerability exists in Post Duplicator for WordPress, affecting versions prior to 3.0.10, where unverified input can be deserialized, allowing attackers with contributor-level access and above to introduce a PHP object into the system. This could potentially enable malicious actions such as deleting files or accessing sensitive information if other vulnerabilities are present on the same system.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings