Yoast Duplicate Post
Yoast Duplicate Post has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2026; all 5 are fixed as of September 2026. Their average CVSS score is 6.2, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high. 2026 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (60%). Other recurring categories include Missing Authorization, SQL Injection.
Every one of the 5 issues recorded for Yoast Duplicate Post has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (2) reported by Unk9vvN. Yoast Duplicate Post is installed on roughly 3,000,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2014-10379Yoast Duplicate Post <= 2.5 - SQL Injection
Read the full analysisVulnerability Records

Yoast Duplicate Post
Author
Yoast
This plugin allows users to clone posts of any type, or copy them to new drafts for further editing. How it works: In ‘Edit Posts’/’Edit Pages’, you can click on ‘Clone’ link below the post/page title: this will immediately create a copy and return to the list. In ‘Edit Posts’/’Edit Pages’, you can select one or more items, then choose ‘Clone’ in the ‘Bulk Actions’ dropdown to copy them all at once. In ‘Edit Posts’/’Edit Pages’, you can click on ‘New Draft’ link below the post/page title. On the post edit screen, you can click on ‘Copy to a new draft’ above “Cancel”/”Move to trash” or in the admin bar. While viewing a post as a logged in user, you can click on ‘Copy to a new draft’ in the admin bar. 3, 4 and 5 will lead to the edit page for the new draft: change what you want, click on ‘Publish’ and you’re done. There is also a template tag, so you can put it in your templates and clone your posts/pages from the front-end. Clicking on the link will lead you to the edit page for the new draft, just like the admin bar link. Duplicate Post has many useful settings to customize its behavior and restrict its use to certain roles or post types. Check out the extensive documentation on yoast.com and our developer docs. Contribute If you find this useful and if you want to contribute, there are two ways: Submit your bug reports, suggestions and requests for features on GitHub; If you want to translate it to your language (there are just a few lines of text), you can use the translation project;
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C