WP Replicate Post

WP Replicate Post has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is SQL Injection, behind 1 of the records (100%).

The one issue recorded for WP Replicate Post has a vendor fix available, so running the current release closes it.

All of these findings were reported by Marco Wotschka. WP Replicate Post is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSHigh
8.8/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all WP Replicate Post vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2023-2237

WP Replicate Post <= 4.0.2 - Authenticated (Contributor+) SQL Injection

Read the full analysis

Vulnerability Records

1 records
WP Replicate Post banner
Latestv4.2
0.0(0)
0/100
Last Updated
2025-10-24 (11mo ago)
Active Installs
100+
Downloads
3,758
Requires WP
3.0+
Requires PHP
0+
Tested up to
WP 6.8.8
Created
2018-06-13 (8y ago)

This plugin has been developed by Yudiz Solutions Ltd. It will help you to replicate pages, posts as well as custom posts. How to use this plugin? 1) In edit posts/pages, you can click on &#8216;Replicate’ link which will create a replica of that particular post/page and return back to the list. 2) This plugin also retains the state of the original post/page. To exemplify, if we create replica of post/page, it will be in the draft state with &#8216;Replica’ name. 3) If you need to edit the replica then it can be done in the same manner as you do with regular post/page. 4) In order to replicate in bulk, you need to select all those posts/pages and then afterward choose &#8216;Replicate’ option from the &#8216;Bulk Actions’ dropdown that appears on the top of the list. 5) Download Source Code from here.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C