Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. yoast/duplicate-post
  4. ›
  5. CVE-2026-1217

CVE-2026-1217: Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite

March 18, 2026 (updated March 19, 2026)

The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn’t have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content.

References

  • github.com/Yoast-dist/duplicate-post
  • github.com/advisories/GHSA-g9w4-m5fx-x3wv
  • nvd.nist.gov/vuln/detail/CVE-2026-1217
  • plugins.trac.wordpress.org/browser/duplicate-post/tags/4.5/src/handlers/bulk-handler.php
  • plugins.trac.wordpress.org/browser/duplicate-post/tags/4.5/src/post-republisher.php
  • www.wordfence.com/threat-intel/vulnerabilities/id/05f175e6-08a9-4199-948c-5bd8b3caaa39?source=cve

Code Behaviors & Features

Detect and mitigate CVE-2026-1217 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 4.6

Fixed versions

  • 4.6

Solution

Upgrade to version 4.6 or above.

Impact 5.4 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-862: Missing Authorization

Source file

packagist/yoast/duplicate-post/CVE-2026-1217.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 24 Mar 2026 12:17:51 +0000.