medium · CVSS v3 6.4
CVE-2026-89424
The Duplicate Post plugin for WordPress is vulnerable to stored XSS via the 'noti_token' parameter. Authenticated users with subscriber-leve
Overview
The Duplicate Post plugin for WordPress is vulnerable to stored XSS via the 'noti_token' parameter. Authenticated users with subscriber-level access can inject scripts that execute when other users view affected pages. This flaw can lead to session hijacking, defacement, or credential theft.
Description
The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin's User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload.
Impact
Confidentiality: user data may be exposed via injected scripts. Integrity: site content can be altered or defaced. Availability: minimal direct impact, but can be leveraged for further attacks. Defenders: site administrators, security teams, and WordPress users with subscriber-level access.
Remediation
Update the Duplicate Post plugin to version 1.5.7 or later. If an update is not possible, disable the 'User Level Permissions' feature for the Subscriber role or remove the plugin entirely. Implement a site-wide Content Security Policy (CSP) to block inline scripts and restrict script sources.
Risk context
Medium severity (CVSS 6.4). No EPSS data available. The vulnerability is exploitable by any authenticated subscriber, making it a moderate risk that should be addressed promptly.
Affected products
- WordPress Duplicate Post plugin 1.5.6
- WordPress Duplicate Post plugin 1.5.5
- WordPress Duplicate Post plugin 1.5.4
- WordPress Duplicate Post plugin 1.5.3
- WordPress Duplicate Post plugin 1.5.2
- WordPress Duplicate Post plugin 1.5.1
- WordPress Duplicate Post plugin 1.5.0
- WordPress Duplicate Post plugin 1.4.9
Scores
- Severity
- medium
- CVSS v2
- 5.5
- CVSS v3
- 6.4
- CVSS v4
- —
- EPSS
- —