SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19435

LOW · CVSS 2.7 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Duplicate Post plugin for WordPress versions prior to 1.5.6 is vulnerable due to inadequate checks on user capabilities, enabling unauthorized users with delegated roles to access sensitive post data, including private and draft content from other users. This could lead to data exposure and privacy breaches within WordPress sites. WordPress administrators and site owners using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-19435
Severity
LOW
CVSS
2.7
EPSS
0.19%
WordPress

Original NVD Description

The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content.