Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.34% | — | Metaphorcreations Post DuplicatorAI | 22/8/2026 | 24/8/2026 | The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `duplicate_post()` function in all versions up to, and including, 3.0.11. This is due to the function not verifying that the user has `edit_others_posts` capability before accepting a… | |
| Aplazada | Media (4.3) | 0.39% | — | Metaphorcreations Post DuplicatorAI | 22/8/2026 | 24/8/2026 | The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capability without checking whether the requesting user holds `publish_posts` or other… | |
| Aplazada | Alta (7.2) | 0.54% | — | Metaphorcreations Post DuplicatorAI | 24/6/2026 | 25/6/2026 | The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, storing attacker-supplied serialized values without the WordPress meta API's double-serialization protection, allowing users with Contributor-level access and above to inject a PHP Object. | |
| Aplazada | Alta (8.8) | 0.52% | — | Metaphorcreations Post DuplicatorAI | 15/6/2026 | 17/6/2026 | Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions. | |
| Aplazada | Media (4.3) | 0.21% | — | Metaphorcreations Post DuplicatorAI | 25/2/2026 | 17/6/2026 | The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all versions up to, and including, 3.0.8. This is due to the `duplicate_post()` function in `includes/api.php` using `$wpdb->insert()` directly to the `wp_postmeta` table instead of WordPress's standard… | |
| Aplazada | Media (4.3) | 0.24% | — | Arulprasadj WP Quick Post DuplicatorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Arul Prasad J WP Quick Post Duplicator wp-quick-post-duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Quick Post Duplicator: from n/a through <= 2.1. | |
| Aplazada | Alta (8.5) | 0.49% | — | Dev02ali Easy Post DuplicatorAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in dev02ali Easy Post Duplicator easy-post-duplicator allows SQL Injection.This issue affects Easy Post Duplicator: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.1) | 0.42% | — | Dev02ali Easy Post DuplicatorAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dev02ali Easy Post Duplicator easy-post-duplicator allows Reflected XSS.This issue affects Easy Post Duplicator: from n/a through <= 1.0.1. | |
| Aplazada | Media (4.3) | 0.17% | — | Rajesh Kumar WP Bulk Post DuplicatorAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Kumar WP Bulk Post Duplicator wp-bulk-post-duplicator allows Cross Site Request Forgery.This issue affects WP Bulk Post Duplicator: from n/a through <= 1.2. | |
| Modificada | Media (4.3) | 0.34% | — | Metaphorcreations Post Duplicator | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in metaphorcreations Post Duplicator post-duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Duplicator: from n/a through <= 2.35. | |
| Modificada | Media (4.3) | 0.31% | — | Metaphorcreations Post Duplicator | 11/1/2025 | 17/6/2026 | The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Modificada | Media (4.3) | 0.42% | — | Metaphorcreations Post Duplicator | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Duplicator: from n/a through 2.31. | |
| Aplazada | Media (5.4) | 0.35% | — | Arulprasadj WP Quick Post DuplicatorAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Arul Prasad J WP Quick Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Quick Post Duplicator: from n/a through 2.0. | |
| Modificada | Media (6.1) | 0.63% | — | Metaphorcreations Post Duplicator | 20/2/2023 | 17/6/2026 | A vulnerability was found in meta4creations Post Duplicator Plugin 2.18 on WordPress. It has been classified as problematic. Affected is the function mtphr_post_duplicator_notice of the file includes/notices.php. The manipulation of the argument post-duplicated leads to cross site scripting. It is possible to launch… | |
| Modificada | Media (5.4) | 0.64% | — | Metaphorcreations Post Duplicator | 10/3/2022 | 17/6/2026 | A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box executes whenever the user opens the Settings Page of the Post Duplicator Plugin or the application root… | |
| Modificada | Alta (8.8) | 0.73% | — | Wpmaz Multisite Post Duplicator | 13/9/2019 | 17/6/2026 | The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF. |