WP Vulnerability WatchVulnerability data as of October 2, 2026

Vulnerability alerts / October 1, 2026

Vulnerability in Duplicate Post — CVE-2026-89424

MediumSeverity
CVSS 6.4
—Estimated exploit probability
EPSS
300,000+ sitesInstalls
1.5.7Fixed in

What to do now

Update Duplicate Post to 1.5.7 or later.

Affected versions

  • Everything up to and including 1.5.6

Affected: Duplicate Post (plugin, copy-delete-posts)

Check: The plugin on wordpress.org / Our record for Duplicate Post

What the vulnerability is

The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin's User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload.

This description is reproduced verbatim from the public vulnerability record.

Sources

See other alerts