WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Duplicate Page and Post

Duplicate post, Duplicate page and Duplicate custom post or clone page and clone post.

4Reported vulnerabilities
8.8Highest CVSS score
2.9.5Latest version
70,000+Active installs

What to do now

Update Duplicate Page and Post to 2.8 or later. 2 of these have a fixed version available. Updating resolves them.

Plugin last updated: September 23, 2024 / Tested up to WordPress: 6.6.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
WF-76044985-477c-4d62-aec3-1905add0a9e2 High 8.8 Before 2.5.7 2.5.7 April 25, 2020
CVE-2026-49046 Medium 6.5 0.3% 2.9.5 and earlier May 27, 2026
CVE-2025-6189 Medium 6.5 0.3% 0 to 2.9.5 (inclusive) September 10, 2025
WF-e8ac3187-b065-434e-9051-d13330dd3da5 Medium 5.5 2.7 and earlier 2.8 July 20, 2022

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.