VendorsMetaphor Creationspost_duplicatorall versions
Vulnerabilities

Metaphor Creations META4CRE8IONS Post Duplicator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2016-15027
meta4creations Post Duplicator Plugin notices.php mtphr_post_duplicator_notice cross site scripting
Published 2023-02-20 · Modified
6.1EPSS 0.006
CVE-2021-33852
A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box executes whenever the user opens the Settings Page of the Post Duplicator Plugin or the application root page after duplicating any of the existing posts.
Published 2022-03-09 · Modified
5.4EPSS 0.006
CVE-2023-49835
WordPress Post Duplicator plugin <= 2.31 - Broken Access Control vulnerability
Published 2024-12-09 · Modified
4.3EPSS 0.004
CVE-2025-24736
WordPress Post Duplicator plugin <= 2.35 - Broken Access Control vulnerability
Published 2025-01-24 · Modified
4.3EPSS 0.003
CVE-2024-12472
Post Duplicator <= 2.36 - Authenticated (Contributor+) Protected Post Disclosure
Published 2025-01-11 · Modified
4.3EPSS 0.003