Copyscape Premium

Copyscape Premium has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.2, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (100%).

Every one of the 2 issues recorded for Copyscape Premium has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Copyscape Premium is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.2/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Copyscape Premium vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2024-47644

Copyscape Premium <= 1.3.8 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

2 records
Copyscape Premium banner
Latestv1.4.2

Copyscape Premium

Copyscape

Author

Copyscape

3.2(10)
64/100
Last Updated
2025-12-24 (9mo ago)
Active Installs
800+
Downloads
58,796
Requires WP
3.0.1+
Requires PHP
0+
Tested up to
WP 6.9.7
Created
2013-04-29 (14y ago)

The Copyscape Premium plugin lets you check if a WordPress post is original before it’s published, by using the Copyscape Premium API to check for duplicate content on the web. The plugin will add a &#8216;Copyscape Check’ button to your WordPress interface, allowing you to check your posts whenever you wish. You may also set the plugin to automatically check your posts when you click &#8216;Publish’ and/or &#8216;Update’. When duplicate content is found, a report of matching pages is shown. You may also see a detailed comparison that highlights your content on the found page. If you do not already have a Copyscape Premium account, please sign up, purchase some credits, and enable your API access. You may then begin using the plugin.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C