yoast/duplicate-post
The go-to tool for cloning posts and pages, including the powerful Rewrite & Republish feature.
Activity
- Latest release
- 6mo ago
- Total releases
- 14
- Cadence
- ~12 days
- Last 12 months
- 3
Reach
- Stars
- 0
Details
- License
- unknown
- First release
- May 26, 2021
| Version | Released | |
|---|---|---|
4.6
minor
| ||
4.6-RC2
pre
1 CVE
CVE-2026-1217
GHSA-g9w4-m5fx-x3wv
Mar 18, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content. Affected versions
4.1.2
4.2
4.2-RC1
4.3
4.3-RC1
4.4
4.4-RC1
4.4-RC2
4.4-RC3
4.5
4.5-RC1
4.6-RC1
+ 1 more Show less
4.6-RC2
Fixed in
4.6
References
Updated Mar 19, 2026 · Source: OSV.dev | ||
4.6-RC1
pre
1 CVE
CVE-2026-1217
GHSA-g9w4-m5fx-x3wv
Mar 18, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content. Affected versions
4.1.2
4.2
4.2-RC1
4.3
4.3-RC1
4.4
4.4-RC1
4.4-RC2
4.4-RC3
4.5
4.5-RC1
4.6-RC1
+ 1 more Show less
4.6-RC2
Fixed in
4.6
References
Updated Mar 19, 2026 · Source: OSV.dev | ||
4.5
minor
1 CVE
CVE-2026-1217
GHSA-g9w4-m5fx-x3wv
Mar 18, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content. Affected versions
4.1.2
4.2
4.2-RC1
4.3
4.3-RC1
4.4
4.4-RC1
4.4-RC2
4.4-RC3
4.5
4.5-RC1
4.6-RC1
+ 1 more Show less
4.6-RC2
Fixed in
4.6
References
Updated Mar 19, 2026 · Source: OSV.dev | ||
4.5-RC1
pre
1 CVE
CVE-2026-1217
GHSA-g9w4-m5fx-x3wv
Mar 18, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content. Affected versions
4.1.2
4.2
4.2-RC1
4.3
4.3-RC1
4.4
4.4-RC1
4.4-RC2
4.4-RC3
4.5
4.5-RC1
4.6-RC1
+ 1 more Show less
4.6-RC2
Fixed in
4.6
References
Updated Mar 19, 2026 · Source: OSV.dev | ||
4.4
minor
1 CVE
CVE-2026-1217
GHSA-g9w4-m5fx-x3wv
Mar 18, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content. Affected versions
4.1.2
4.2
4.2-RC1
4.3
4.3-RC1
4.4
4.4-RC1
4.4-RC2
4.4-RC3
4.5
4.5-RC1
4.6-RC1
+ 1 more Show less
4.6-RC2
Fixed in
4.6
References
Updated Mar 19, 2026 · Source: OSV.dev | ||
4.4-RC3
pre
1 CVE
CVE-2026-1217
GHSA-g9w4-m5fx-x3wv
Mar 18, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content. Affected versions
4.1.2
4.2
4.2-RC1
4.3
4.3-RC1
4.4
4.4-RC1
4.4-RC2
4.4-RC3
4.5
4.5-RC1
4.6-RC1
+ 1 more Show less
4.6-RC2
Fixed in
4.6
References
Updated Mar 19, 2026 · Source: OSV.dev | ||
4.4-RC2
pre
1 CVE
CVE-2026-1217
GHSA-g9w4-m5fx-x3wv
Mar 18, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content. Affected versions
4.1.2
4.2
4.2-RC1
4.3
4.3-RC1
4.4
4.4-RC1
4.4-RC2
4.4-RC3
4.5
4.5-RC1
4.6-RC1
+ 1 more Show less
4.6-RC2
Fixed in
4.6
References
Updated Mar 19, 2026 · Source: OSV.dev | ||
4.4-RC1
pre
1 CVE
CVE-2026-1217
GHSA-g9w4-m5fx-x3wv
Mar 18, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content. Affected versions
4.1.2
4.2
4.2-RC1
4.3
4.3-RC1
4.4
4.4-RC1
4.4-RC2
4.4-RC3
4.5
4.5-RC1
4.6-RC1
+ 1 more Show less
4.6-RC2
Fixed in
4.6
References
Updated Mar 19, 2026 · Source: OSV.dev | ||
4.3
minor
1 CVE
CVE-2026-1217
GHSA-g9w4-m5fx-x3wv
Mar 18, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content. Affected versions
4.1.2
4.2
4.2-RC1
4.3
4.3-RC1
4.4
4.4-RC1
4.4-RC2
4.4-RC3
4.5
4.5-RC1
4.6-RC1
+ 1 more Show less
4.6-RC2
Fixed in
4.6
References
Updated Mar 19, 2026 · Source: OSV.dev | ||
4.3-RC1
pre
1 CVE
CVE-2026-1217
GHSA-g9w4-m5fx-x3wv
Mar 18, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content. Affected versions
4.1.2
4.2
4.2-RC1
4.3
4.3-RC1
4.4
4.4-RC1
4.4-RC2
4.4-RC3
4.5
4.5-RC1
4.6-RC1
+ 1 more Show less
4.6-RC2
Fixed in
4.6
References
Updated Mar 19, 2026 · Source: OSV.dev | ||
4.2
minor
1 CVE
CVE-2026-1217
GHSA-g9w4-m5fx-x3wv
Mar 18, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content. Affected versions
4.1.2
4.2
4.2-RC1
4.3
4.3-RC1
4.4
4.4-RC1
4.4-RC2
4.4-RC3
4.5
4.5-RC1
4.6-RC1
+ 1 more Show less
4.6-RC2
Fixed in
4.6
References
Updated Mar 19, 2026 · Source: OSV.dev | ||
4.2-RC1
pre
1 CVE
CVE-2026-1217
GHSA-g9w4-m5fx-x3wv
Mar 18, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content. Affected versions
4.1.2
4.2
4.2-RC1
4.3
4.3-RC1
4.4
4.4-RC1
4.4-RC2
4.4-RC3
4.5
4.5-RC1
4.6-RC1
+ 1 more Show less
4.6-RC2
Fixed in
4.6
References
Updated Mar 19, 2026 · Source: OSV.dev | ||
4.1.2
initial
1 CVE
CVE-2026-1217
GHSA-g9w4-m5fx-x3wv
Mar 18, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content. Affected versions
4.1.2
4.2
4.2-RC1
4.3
4.3-RC1
4.4
4.4-RC1
4.4-RC2
4.4-RC3
4.5
4.5-RC1
4.6-RC1
+ 1 more Show less
4.6-RC2
Fixed in
4.6
References
Updated Mar 19, 2026 · Source: OSV.dev |