SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19085

LOW · CVSS 2.7 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Duplicate Post plugin for WordPress prior to version 1.5.6 is vulnerable as it fails to verify user permissions before allowing the duplication of password-protected posts. This oversight enables users with delegated roles to potentially expose sensitive content by republishing it as publicly accessible. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized content exposure.

CVE
CVE-2026-19085
Severity
LOW
CVSS
2.7
EPSS
0.18%
WordPress

Original NVD Description

The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable.