Metaphorcreations
Metaphorcreations Post Duplicator: vulnerabilidades y CVE
Metaphorcreations Post Duplicator tiene 10 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-4244 | Media (4.3) | 0.34% | — | 22 ago 2026 | The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `duplicate_post()` function in all versions up to, and including, 3.0.11. This is due… |
| CVE-2026-4245 | Media (4.3) | 0.39% | — | 22 ago 2026 | The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the… |
| CVE-2026-10749 | Alta (7.2) | 0.54% | — | 24 jun 2026 | The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, storing attacker-supplied serialized values without the WordPress meta API's double-serialization… |
| CVE-2026-39474 | Alta (8.8) | 0.52% | — | 15 jun 2026 | Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions. |
| CVE-2026-2301 | Media (4.3) | 0.21% | — | 25 feb 2026 | The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all versions up to, and including, 3.0.8. This is due to the `duplicate_post()` function in… |
| CVE-2025-24736 | Media (4.3) | 0.34% | — | 24 ene 2025 | Missing Authorization vulnerability in metaphorcreations Post Duplicator post-duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Duplicator: from n/a through <=… |
| CVE-2024-12472 | Media (4.3) | 0.31% | — | 11 ene 2025 | The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() function due to insufficient restrictions on which posts can be… |
| CVE-2023-49835 | Media (4.3) | 0.42% | — | 9 dic 2024 | Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Duplicator: from n/a through 2.31. |
| CVE-2016-15027 | Media (6.1) | 0.63% | — | 20 feb 2023 | A vulnerability was found in meta4creations Post Duplicator Plugin 2.18 on WordPress. It has been classified as problematic. Affected is the function mtphr_post_duplicator_notice of the file includes/notices.php. The… |
| CVE-2021-33852 | Media (5.4) | 0.64% | — | 10 mar 2022 | A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.