Feed/CVE-2026-19435
CVE-2026-19435

CVE-2026-19435

Published Aug 21, 2026·Updated Aug 21, 2026

NVD Description

The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free