PT-2026-7608 · WordPress · Duplicate Post

Unk9Vvn

·

Publicado

2026-02-11

·

Atualizado

2026-02-11

·

CVE-2019-25314

CVSS v3.1

5.5

Média

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Duplicate-Post WordPress Plugin version 3.2.3
Description The Duplicate-Post WordPress Plugin version 3.2.3 has a persistent cross-site scripting issue in the plugin settings parameters. An attacker can inject malicious scripts into the title prefix, suffix, menu order, and blacklist fields. This allows for the execution of arbitrary JavaScript in the admin interfaces. The vulnerable parameters include title prefix, suffix, menu order, and blacklist.
Recommendations Update Duplicate-Post WordPress Plugin to a newer version that addresses this issue. As a temporary workaround, sanitize all input to the title prefix, suffix, menu order, and blacklist fields.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-25314

Produtos afetados

Duplicate Post