PT-2026-7608 · WordPress · Duplicate Post
Unk9Vvn
·
Publicado
2026-02-11
·
Atualizado
2026-02-11
·
CVE-2019-25314
CVSS v3.1
5.5
Média
| Vetor | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Duplicate-Post WordPress Plugin version 3.2.3
Description
The Duplicate-Post WordPress Plugin version 3.2.3 has a persistent cross-site scripting issue in the plugin settings parameters. An attacker can inject malicious scripts into the title prefix, suffix, menu order, and blacklist fields. This allows for the execution of arbitrary JavaScript in the admin interfaces. The vulnerable parameters include
title prefix, suffix, menu order, and blacklist.Recommendations
Update Duplicate-Post WordPress Plugin to a newer version that addresses this issue. As a temporary workaround, sanitize all input to the
title prefix, suffix, menu order, and blacklist fields.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Duplicate Post