Quttera - eCommerce Security[verified]@MNovofastovskyPatch
Critical WordPress plugin vulnerability CVE-2026-1499 permits arbitrary file upload and remote code execution; users should update or remove the plugin and audit capabilities to mitigate the risk.
CVEFind.com@CveFindComPatch
A critical CVE (CVE-2026-1499) in the WP Duplicate plugin allows arbitrary file uploads via AJAX, potentially enabling remote code execution; users should immediately update to version 1.1.9 to mitigate the risk.
CVE@CVEnewDisclosure
A missing‑authorization flaw in the WP Duplicate plugin enables arbitrary file uploads in all versions up to 1.1.8.
CRAC Learning - Tech@cracbotDisclosure
CVE-2026-1499 is a critical WordPress plugin vulnerability that allows arbitrary file uploads due to missing authorization, currently awaiting further analysis.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
CVE-2026-1499 is a WordPress WP Duplicate Plugin vulnerability that permits authenticated users to upload arbitrary files, leading to remote code execution.
0day Signal@0dayPublishingExploit
The tweet discloses CVE-2026-1499 in WP Duplicate, outlining a chained AJAX and path traversal exploit that achieves RCE via authentication bypass, and provides a link to the vulnerability details.