CVE · Medium

CVE-2026-53739 — Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-53739 Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed) Cross-Site Request Forgery (CSRF) Medium 4.3 < 4.6 4.6 2026-06-10

CVE-2026-53739

Yoast Duplicate Post version 4.6 and earlier is susceptible to a cross-site request forgery vulnerability in its duplicate_post_dismiss_notice handler, which fails to check for a nonce or capability verification. This allows attackers to deceive authenticated users into triggering a request that disables the admin notice globally across the network.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.