Feed/CVE-2026-19077
CVE-2026-19077MEDIUMCVSS 6.5

CVE-2026-19077

Published Aug 10, 2026·Updated Aug 11, 2026

NVD Description

The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free