Duplicate Page and Post
Duplicate Page and Post has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2026; 4 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2022 was the busiest year with 2 disclosures.
The most common weakness is SQL Injection, behind 3 of the records (60%). Other recurring categories include Cross-Site Scripting.
4 of the records (80%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
4 independent researchers contributed these findings, one record each. Duplicate Page and Post is installed on roughly 70,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-6189Duplicate Page and Post <= 2.9.5 - Authenticated (Contributor+) SQL Injection via meta_key Parameter
Read the full analysisVulnerability Records

Duplicate Page and Post
Author
Arjun Thakur
Duplicate Page and Post provides a simple way to create a clone of pages, posts and custom post types. The duplicate can be created with the post status selected in the plugin settings. The plugin is lightweight and focused on fast, straightforward content duplication. Major features of this plugin include Create a clone of a particular page. Create a clone of a particular post. Create a clone of a particular custom post type (CPT). Option to select editor (Classic and Gutenberg). Option to add a post suffix. Option to add custom text for the duplicate link button. Option to select the status of duplicated posts. Option to select the redirect behavior after duplication. Like the plugin? If you find the plugin useful, your feedback is appreciated.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C