Duplicate PP
Duplicate PP has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).
The one issue recorded for Duplicate PP has a vendor fix available, so running the current release closes it.
All of these findings were reported by Webbernaut. Duplicate PP is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-12538Duplicate Post, Page and Any Custom Post <= 3.5.5 - Authenticated (Contributor+) Post Disclosure via Post Duplication
Read the full analysisVulnerability Records

Duplicate PP
Author
Binsaifullah
Duplicate PP is a simple and light-weight plugin which allows you to duplicate any Post,Page and Any Custom Post Type Easily. The duplicated Post or Page or CPT acts as draft. You can either duplicate the post, page or any custom post type using dashboard at the backend or from the single post view at the frontend. Features Include: Duplicate the POST Duplicate the PAGE Duplicate Any Custom POST TYPE Duplicate from Backend Duplicate from Frontend (Single Post View)
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C