CVE-2026-19435: Copy & Delete Posts < 1.5.6 - Authenticated Arbitrary Post Content and Password Disclosure
The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content.
Affected Software
Event History
Frequently Asked Questions
Which users are realistically able to exploit this issue?
Any user assigned a delegated WordPress role may be able to exploit it. The plugin fails to verify that the user has the required capability before returning post data.
What information could be exposed?
An affected user can read post content, metadata, and passwords for posts they are not authorized to access. This includes private posts and draft content created by other users.
Are only published posts affected?
No. The disclosed data can include other users' private posts and drafts, in addition to their associated metadata and passwords.