CVE-2026-19085 PUBLISHED

Copy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure

Assigner: WPScan
Reserved: 06.08.2026 Published: 21.08.2026 Updated: 21.08.2026

The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable.

Product Status

Vendor Unknown
Product Duplicate Post
Versions Default: unaffected
  • affected from 0 to 1.5.6 (excl.)

Credits

  • Erwan LR (WPScan) finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE