Metaphor Creations Post Duplicator
cpe:2.3:a:metaphorcreations:post_duplicator:*:*:*:*:wordpress:*:*
- <= 2.36
A vulnerability allowing information exposure has been identified in the Post Duplicator plugin for WordPress, affecting all versions through 2.36. The issue arises in the mtphr_duplicate_post() function, where inadequate restrictions allow authenticated attackers with Contributor-level access and above to duplicate posts and access data from password-protected, private, or draft posts that should be off-limits.
Exploitation of this vulnerability could lead to unauthorized access to sensitive post data, including information from password-protected, private, or draft posts.
Users are advised to update the Post Duplicator plugin to version 2.37 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.