CVE-2026-19085: Copy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure

Published Aug 21, 2026
·
Updated

The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable.

Affected Software

1 affected component
WordPress Duplicate Post<1.5.6

Event History

Aug 21, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A user with a delegated role who can duplicate posts can exploit the issue. The flaw allows that user to duplicate another user's password-protected post without first being authorized to read its content.

2

What content is at risk?

Password-protected posts are affected. An attacker can republish the duplicated content so that it is publicly readable.

3

Which plugin versions are affected?

Versions of Duplicate Post before 1.5.6 are affected. Updating to version 1.5.6 or later addresses the described issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203