CVE-2026-19085: Copy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure
Published Aug 21, 2026
·Updated
The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable.
Affected Software
1 affected component
WordPress Duplicate Post<1.5.6
Event History
Aug 21, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A user with a delegated role who can duplicate posts can exploit the issue. The flaw allows that user to duplicate another user's password-protected post without first being authorized to read its content.
2
What content is at risk?
Password-protected posts are affected. An attacker can republish the duplicated content so that it is publicly readable.
3
Which plugin versions are affected?
Versions of Duplicate Post before 1.5.6 are affected. Updating to version 1.5.6 or later addresses the described issue.