WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Yoast Duplicate Post

The go-to tool for cloning posts and pages, including the powerful Rewrite & Republish feature.

4Reported vulnerabilities
9.8Highest CVSS score
4.7Latest version
3,000,000+Active installs

What to do now

Update Yoast Duplicate Post to 4.6 or later. 4 of these have a fixed version available. Updating resolves them.

Plugin last updated: June 22, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2014-10379 Critical 9.8 1.8% Before 2.6 2.6 August 21, 2019
CVE-2014-10378 Medium 6.1 0.9% Before 2.6 2.6 August 21, 2019
CVE-2026-1217 Medium 5.4 0.2% 0 to 4.5 (inclusive) 4.6 March 18, 2026
CVE-2019-25314 Medium 4.8 0.2% 0.3 to 3.2.3 (inclusive) 3.2.4 February 11, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.