Duplicate Content Cure
Duplicate Content Cure has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Duplicate Content Cure has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Muhammad Nur Ibnu Hubab. Duplicate Content Cure is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.2.39.
CVE-2025-59132Duplicate Content Cure <= 1.0 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Duplicate Content Cure
Author
Badi Jones
Duplicate Content Cure is an extremely simple plugin that makes WordPress more Search Engine friendly (And therefore improving SEO). It does this by preventing search engine spiders/bots from accessing pages like Archives, Tags, and Categories, which tend to contain duplicated content from elsewhere on your site. This is achieved by adding nofollow, noindex to these problem pages. Duplicate Content Cure doesn’t have a lot of features that other SEO plugins have, but it also is lightning fast by comparison.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C