WP Clone any post type
WP Clone any post type has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.4 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 1 of the records (50%). Other recurring categories include Open Redirect.
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
All of these findings were reported by Abdi Pranata. WP Clone any post type is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-31872WP Clone any post type <= 3.6 - Missing Authorization
Read the full analysisVulnerability Records

WP Clone any post type
Author
Galaxy Weblinks
This plugin allows users to create duplicate posts for any post type, or copy them to the new drafts for further editing. Also, it makes an exact number of copies of the selected post, page and custom post types. HOW IT WORKS On the ‘Clone Settings’ page, select the elements which you want to clone. In Edit Posts, Edit Pages and Edit Post for custom post type you can click on the ‘Clone’ link below the title, this will immediately create a clone and return to the list. In Edit Posts, Edit Pages and Edit Post for the custom post type, you can select one or more items, then choose ‘Clone’ in the ‘Bulk Actions’ drop-down to clone them all at once. FEATURES Creates a duplicate copy of the selected post, page, and custom post type. Creates numerous duplicate copies of selected items. Cloning multiple bulk posts, pages and custom post type of selected items at a single click. Here’s a link to the documentation for the plugin. This will help you learn more about its features and how to use it. Documentation For any feedback or queries regarding this plugin, please contact our Support team.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C