PLUGIN SECURITY
Is Post Duplicator safe?
Creates functionality to duplicate any and all post types, including taxonomies & custom fields. Perfect for developers and content creators.
What this plugin does
- Slug:
post-duplicator - Author: metaphorcreations
- 200000+ active installs
- 96/100 rating (80 reviews on wordpress.org)
- 4984627 all-time downloads
- On WordPress.org since 2012-04-28
duplicateduplicationpostposts
Maintenance status
- Latest known version: 3.0.15
- Last updated: 2026-08-22 4:30pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
10 known CVEs on file for Post Duplicator.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-4245 | Post Duplicator [post-duplicator] < 3.0.12 | Incorrect Authorization | Medium 4.3 | < 3.0.12 | 3.0.12 | 2026-08-21 | ✓ fixed in latest |
| CVE-2026-4244 | Post Duplicator [post-duplicator] < 3.0.12 | Missing Authorization | Medium 4.3 | < 3.0.12 | 3.0.12 | 2026-08-21 | ✓ fixed in latest |
| CVE-2026-10749 | Post Duplicator [post-duplicator] < 3.0.15 | Deserialization of Untrusted Data | Unknown | < 3.0.15 | 3.0.15 | 2026-06-24 | ✓ fixed in latest |
| CVE-2026-39474 | Post Duplicator [post-duplicator] < 3.0.11 | Deserialization of Untrusted Data | High 8.8 | < 3.0.11 | 3.0.11 | 2026-04-13 | ✓ fixed in latest |
| CVE-2025-24736 | Post Duplicator [post-duplicator] < 2.36 | Missing Authorization | Medium 4.3 | < 2.36 | 2.36 | 2025-01-24 | ✓ fixed in latest |
| CVE-2024-12472 | Post Duplicator [post-duplicator] < 2.37 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 2.37 | 2.37 | 2025-01-10 | ✓ fixed in latest |
| CVE-2023-49835 | Post Duplicator [post-duplicator] < 2.32 | Missing Authorization | Medium 4.3 | < 2.32 | 2.32 | 2023-12-05 | ✓ fixed in latest |
| CVE-2021-33852 | Post Duplicator [post-duplicator] < 2.27 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.27 | 2.27 | 2021-12-02 | ✓ fixed in latest |
+ 6 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Post Duplicator [post-duplicator] < 2.17 | — | Unknown | < 2.17 | 2.17 | 2016-04-06 | ✓ fixed in latest |
| CVE-2016-15027 | Post Duplicator [post-duplicator] < 2.17 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.17 | 2.17 | 2016-04-06 | ✓ fixed in latest |
| — | Post Duplicator [post-duplicator] < 3.0.9 | — | Unknown | < 3.0.9 | 3.0.9 | 0000-00-00 | ✓ fixed in latest |
| — | Post Duplicator [post-duplicator] < 2.17 | — | Unknown | < 2.17 | 2.17 | — | ✓ fixed in latest |
| — | Post Duplicator <= 2.16 - Cross-Site Scripting (XSS) | — | Unknown | < 2.17 | 2.17 | — | ✓ fixed in latest |
| CVE-2026-2301 | Post Duplicator < 3.0.9 - Missing Authorization to Authenticated (Contributor+) Protected Post Meta Insertion via 'customMetaData' Parameter | — | Unknown | < 3.0.9 | 3.0.9 | — | ✓ fixed in latest |
How to fix it
Keep Post Duplicator updated — 3.0.15 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WPvivid — Backup, Migration & Staging — 900000+ active installs — 98/100 (1535) — max PHP <8.0
- Duplicate Menu — 100000+ active installs — 92/100 (104) — max PHP 8.4
- Custom Product Tabs for WooCommerce — 80000+ active installs — 88/100 (163) — max PHP 8.4
- Clone — 40000+ active installs — 82/100 (339)
- Prepare New Version — 6000+ active installs — 96/100 (6)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.