Known vulnerabilities in PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes
Control how published content is updated. Users can duplicate posts and submit changes. Then editors can approve, reject or schedule those changes.
4Reported vulnerabilities
7.5Highest CVSS score
3.9.2Latest version
10,000+Active installs
What to do now
Update PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes to 3.7.24 or later.
4 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-32539 | High | 0.2% | 3.7.23 and earlier | 3.7.24 |
March 20, 2026 |
| CVE-2024-9436 | Medium | 0.4% | 0 to 3.5.14 (inclusive) | 3.5.15 |
October 11, 2024 |
| CVE-2026-25322 | Medium | 0.1% | 3.7.22 and earlier | 3.7.23 |
January 29, 2026 |
| CVE-2024-11154 | Medium | 0.4% | 0 to 3.5.15 (inclusive) 0 to 3.5.15 (inclusive) |
3.5.16 |
November 20, 2024 |