CVE · High

CVE-2026-39474 — Post Duplicator [post-duplicator] < 3.0.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-39474 Post Duplicator [post-duplicator] < 3.0.11 Deserialization of Untrusted Data High 8.8 < 3.0.11 3.0.11 2026-04-13

CVE-2026-39474

A vulnerability exists in Post Duplicator for WordPress, affecting versions prior to 3.0.10, where unverified input can be deserialized, allowing attackers with contributor-level access and above to introduce a PHP object into the system. This could potentially enable malicious actions such as deleting files or accessing sensitive information if other vulnerabilities are present on the same system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.