Post Cloner

Post Cloner has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Post Cloner has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Nabil Irawan. Post Cloner is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.4.10.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Post Cloner vulnerabilities before they are exploited.

Most severe open issueCVSS 5.3CVE-2025-62865

Post Cloner <= 1.0.0 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Post Cloner banner
Latestv1.0.0
4.8(9)
96/100
Last Updated
2023-12-13 (3y ago)
Active Installs
1,000+
Downloads
25,117
Requires WP
3.5+
Requires PHP
0+
Tested up to
WP 6.4.10
Created
2015-09-18 (11y ago)

Post Cloner will create a quick to access action button on the post/page edit screen alongside &#8216;Edit’, &#8216;Quick Edit’, &#8216;Trash’ and &#8216;View’. All cloned posts, pages and custom post types will have &#8216;- Clone’ appended to the end of their title. All cloned posts, pages and custom post types will also be set to draft so they don’t appear anywhere on your site until you decide to publish them. Features Clone posts, pages and custom post types Full control over what is clone-able (Example: Enable cloning pages but disabled for posts) Works with Easy Digital Downloads Complete clone of posts/pages including taxonomies and meta data (includes featured images, categories, tags and any custom metadata assigned to the post/page/custom post type) Lightweight, compact solution Nonce checks implemented for security High quality code adhering to WordPress Coding Standards FuturePlans Additional settings to adjust post data of the new cloned post

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C