Security Advisory

CVE-2026-19435

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-21 06:00:17
Last updated 2026-08-21 12:52:50
Assigner WPScan
CVSS score 2.7
State PUBLISHED

Description

The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content.