The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'saveSettings' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify plugin settings that control role capabilities, and subsequently exploit the misconfigured capabilities to duplicate and view password-protected posts containing sensitive information.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Nov 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ninjateam
Ninjateam wp Duplicate Page Wordpress Wordpress wordpress |
|
| Vendors & Products |
Ninjateam
Ninjateam wp Duplicate Page Wordpress Wordpress wordpress |
Tue, 18 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'saveSettings' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify plugin settings that control role capabilities, and subsequently exploit the misconfigured capabilities to duplicate and view password-protected posts containing sensitive information. | |
| Title | WP Duplicate Page <= 1.7 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-18T09:27:38.298Z
Updated: 2025-11-18T21:02:09.424Z
Reserved: 2025-10-29T17:11:16.657Z
Link: CVE-2025-12481
Updated: 2025-11-18T21:01:35.065Z
Status : Awaiting Analysis
Published: 2025-11-18T10:15:47.920
Modified: 2025-11-18T14:06:29.817
Link: CVE-2025-12481
No data.