Post Cloner
Post Cloner has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Post Cloner has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nabil Irawan. Post Cloner is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.4.10.
CVE-2025-62865Post Cloner <= 1.0.0 - Missing Authorization
Read the full analysisVulnerability Records

Post Cloner
Author
Evan Herman
Post Cloner will create a quick to access action button on the post/page edit screen alongside ‘Edit’, ‘Quick Edit’, ‘Trash’ and ‘View’. All cloned posts, pages and custom post types will have ‘- Clone’ appended to the end of their title. All cloned posts, pages and custom post types will also be set to draft so they don’t appear anywhere on your site until you decide to publish them. Features Clone posts, pages and custom post types Full control over what is clone-able (Example: Enable cloning pages but disabled for posts) Works with Easy Digital Downloads Complete clone of posts/pages including taxonomies and meta data (includes featured images, categories, tags and any custom metadata assigned to the post/page/custom post type) Lightweight, compact solution Nonce checks implemented for security High quality code adhering to WordPress Coding Standards FuturePlans Additional settings to adjust post data of the new cloned post
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C