CyberRota Analysis
AI-GeneratedThe Duplicate Post plugin for WordPress versions prior to 1.5.6 is vulnerable due to inadequate checks on user capabilities, enabling unauthorized users with delegated roles to access sensitive post data, including private and draft content from other users. This could lead to data exposure and privacy breaches within WordPress sites. WordPress administrators and site owners using this plugin should prioritize updating to the latest version to mitigate potential risks.
Original NVD Description
The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content.