rootpwn

medium · CVSS v3 6.4

CVE-2026-89424

The Duplicate Post plugin for WordPress is vulnerable to stored XSS via the 'noti_token' parameter. Authenticated users with subscriber-leve

Overview

The Duplicate Post plugin for WordPress is vulnerable to stored XSS via the 'noti_token' parameter. Authenticated users with subscriber-level access can inject scripts that execute when other users view affected pages. This flaw can lead to session hijacking, defacement, or credential theft.

Description

The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin's User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload.

Impact

Confidentiality: user data may be exposed via injected scripts. Integrity: site content can be altered or defaced. Availability: minimal direct impact, but can be leveraged for further attacks. Defenders: site administrators, security teams, and WordPress users with subscriber-level access.

Remediation

Update the Duplicate Post plugin to version 1.5.7 or later. If an update is not possible, disable the 'User Level Permissions' feature for the Subscriber role or remove the plugin entirely. Implement a site-wide Content Security Policy (CSP) to block inline scripts and restrict script sources.

Risk context

Medium severity (CVSS 6.4). No EPSS data available. The vulnerability is exploitable by any authenticated subscriber, making it a moderate risk that should be addressed promptly.

Affected products

  • WordPress Duplicate Post plugin 1.5.6
  • WordPress Duplicate Post plugin 1.5.5
  • WordPress Duplicate Post plugin 1.5.4
  • WordPress Duplicate Post plugin 1.5.3
  • WordPress Duplicate Post plugin 1.5.2
  • WordPress Duplicate Post plugin 1.5.1
  • WordPress Duplicate Post plugin 1.5.0
  • WordPress Duplicate Post plugin 1.4.9

Scores

Severity
medium
CVSS v2
5.5
CVSS v3
6.4
CVSS v4
—
EPSS
—

WordPress XSS Duplicate Post Stored XSS Subscriber Medium CSP

← All CVEs