PT-2026-7608 · WordPress · Duplicate Post

Unk9Vvn

·

Published

2026-02-11

·

Updated

2026-02-11

·

CVE-2019-25314

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Duplicate-Post WordPress Plugin version 3.2.3
Description The Duplicate-Post WordPress Plugin version 3.2.3 has a persistent cross-site scripting issue in the plugin settings parameters. An attacker can inject malicious scripts into the title prefix, suffix, menu order, and blacklist fields. This allows for the execution of arbitrary JavaScript in the admin interfaces. The vulnerable parameters include title prefix, suffix, menu order, and blacklist.
Recommendations Update Duplicate-Post WordPress Plugin to a newer version that addresses this issue. As a temporary workaround, sanitize all input to the title prefix, suffix, menu order, and blacklist fields.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25314

Affected Products

Duplicate Post