CVE-2024-12472: Post Duplicator <= 2.36 - Authenticated (Contributor+) Protected Post Disclosure
The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphrduplicatepost() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to by duplicating the post.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12472?
CVE-2024-12472 is classified as a moderate-severity vulnerability due to potential information exposure.
How do I fix CVE-2024-12472?
To fix CVE-2024-12472, update the Post Duplicator plugin to version 2.37 or later.
What type of vulnerability is CVE-2024-12472?
CVE-2024-12472 is an Information Exposure vulnerability affecting the Post Duplicator plugin.
Who is affected by CVE-2024-12472?
Authenticated users with contributor-level access in WordPress may exploit CVE-2024-12472.
What component of WordPress is impacted by CVE-2024-12472?
CVE-2024-12472 affects the mtphr_duplicate_post() function in the Post Duplicator plugin.