Skip to content
EXPLOIT
.CC
CVEs
Search
About
synced 13 MIN AGO
T-13M
01
Record
STATE: —
02
Description
SRC: CNA
03
Metadata
SCHEMA: CVE JSON 5
04
Affected products
PAIRS: —
05
References
REFS: —
01
Record
STATE: PUBLISHED
CVE-2026-4245
Post Duplicator <= 3.0.11 - Authorization Bypass to Authenticated (Contributor+) Post Duplication
Medium
PUBLISHED
CNA: Wordfence
Base score
4.3
CVSS v3.x
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
View raw JSON
CVE Program record
02
Description
CNA: Wordfence
Post Duplicator <= 3.0.11 - Authorization Bypass to Authenticated (Contributor+) Post Duplication
03
Metadata
SCHEMA: 5.2
Published
2026-08-22 11:30Z
2 HR AGO
Last updated
2026-08-22 11:30Z
2 HR AGO
Reserved
2026-03-15
Assigning CNA
Wordfence
Record state
PUBLISHED
Severity
Medium (CVSS 4.3)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weaknesses
CWE-863
Incorrect Authorization
Class
SSVC decision
No CISA-ADP assessment
Data version
5.2
Document digest
0850dfd13356f2fd4c88161dddc29f643922af245b00f6743a080645cf5568d0
04
Affected products
PAIRS: 1
Vendor
Product
Versions
Platforms
metaphorcreations
Post Duplicator
0 to 3.0.11
—
05
References
REFS: 6
www.wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/bb671c8f-9e14-4f79-adfa-72f48ec02449?source=cve
plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/post-duplicator/trunk/includes/api.php#L520
plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/post-duplicator/trunk/includes/api.php#L635
plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/post-duplicator/trunk/includes/api.php#L740
plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/post-duplicator/trunk/includes/api.php#L624
plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3485579/