
CVE-2026-1217 The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() an… https://www.cve.org/CVERecord?id=CVE-2026-1217
Post summary
The Yoast Duplicate Post WordPress plugin has a flaw allowing unauthorized data modification due to a missing capability check, but no proof of concept, active exploitation, fix, or tool is detailed.

