WordPress Plugin Vulnerabilities

Post Duplicator < 2.32 - Missing Authorization via mtphr_duplicate_post

Description

The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mtphr_duplicate_post function in versions up to, and including, 2.31. This makes it possible for authenticated attackers, with contributor-level access and above, to publish posts upon duplication.

Affects Plugins

Fixed in 2.32

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Huynh Tien Si
Verified
No

Timeline

Publicly Published
2023-12-05 (about 2 years ago)
Added
2023-12-08 (about 2 years ago)
Last Updated
2023-12-08 (about 2 years ago)

Other