CVE-2026-19085
Received Received - Intake

Duplicate Post Plugin Password-Protected Post Exposure

Vulnerability report for CVE-2026-19085, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: WPScan

Description

The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wpseek duplicate_post to 1.5.6 (exc)
wpseek copy_and_delete_posts to 1.5.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin 'Copy & Delete Posts' versions before 1.5.6. It allows users with delegated roles like Author or higher to duplicate and republish another user's password-protected post as publicly readable without proper authorization checks. The issue occurs due to missing verification of a user's permission to read the post content before duplication.

Detection Guidance

Check the installed version of the 'Copy & Delete Posts' plugin. If it is below 1.5.6, the system is vulnerable. Use WordPress admin panel or run: wp plugin list | grep 'Copy & Delete Posts' in the WordPress directory.

Impact Analysis

If you use the affected plugin version, an attacker with a delegated role could access and republish your password-protected posts publicly. This could expose sensitive information intended to be restricted. The impact is limited to users with delegated roles exploiting the flaw.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of sensitive data, potentially violating GDPR or HIPAA requirements for data protection and access controls. Organizations using the plugin may face compliance risks if data is exposed.

Mitigation Strategies

Update the 'Copy & Delete Posts' plugin to version 1.5.6 or later immediately. Restrict user roles to prevent unauthorized access until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19085. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart