CVE-2026-1499Disclosure

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to a missing capability check on the `process_add_site()` AJAX action combined with path traversal in the file upload functionality. This makes it possible for authenticated (subscriber-level) attackers to set the internal `prod_key_random_id` option, which can then be used by an unauthenticated attacker to bypass authentication checks and write arbitrary files to the server via the `handle_upload_single_big_file()` function, ultimately leading to remote code execution.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-06); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-06: 4Mentions · 2026-02-11: 1Mentions · 2026-02-22: 1PoC Mentioned / Linked · 2026-02-06: 1Exploit Tool / Code · 2026-02-06: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-22: 1Technical Details · 2026-02-06: 4Technical Details · 2026-02-11: 1Technical Details · 2026-02-22: 102-0602-1102-22
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
Exploit
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-064
Disclosure2Exploit1Patch1
2026-02-111
Disclosure1
2026-02-221
Patch1
Full discourse6 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-1499: CRITICAL] Vulnerability in WP Duplicate plugin allows arbitrary file upload via AJAX action, potentially leading to remote code execution on WordPress sites. Update to version 1.1.9 for security.#cve,CVE-2026-1499,#cybersecurity https://cvefind.com/CVE-2026-1499

    Post summary

    A critical CVE (CVE-2026-1499) in the WP Duplicate plugin allows arbitrary file uploads via AJAX, potentially enabling remote code execution; users should immediately update to version 1.1.9 to mitigate the risk.

    0101092
    583 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1499 The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to … https://www.cve.org/CVERecord?id=CVE-2026-1499

    Post summary

    A missing‑authorization flaw in the WP Duplicate plugin enables arbitrary file uploads in all versions up to 1.1.8.

    00010174
    56.5K followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    Critical WordPress plugin zero-day (CVE-2026-1499)! The WP Duplicate plugin (≤1.1.8) suffers from missing authorization in its process_add_site() AJAX upload endpoint, allowing arbitrary file uploads & remote code execution. Score 9.8 CRITICAL. https://nvd.nist.gov/vuln/detail/CVE-2026-1499 🔒 If you’re running e-commerce on WordPress, this means potential full site compromise via a flaw that lets attackers write and execute files on your server. 🛠 Fix: Update/remove the plugin immediately & audit user capabilities. Then scan for malware or backdoors. More on cleanup → https://quttera.com/remove-malware-from-website #WordPress #CVE20261499 #WPduplicate #Infosec #WebSecurity

    Post summary

    Critical WordPress plugin vulnerability CVE-2026-1499 permits arbitrary file upload and remote code execution; users should update or remove the plugin and audit capabilities to mitigate the risk.

    0000067
    37 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-1499 (CVSS:9.8, CRITICAL) is Awaiting Analysis. The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all ver..https://nvd.nist.gov/vuln/detail/CVE-2026-1499 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-1499 is a critical WordPress plugin vulnerability that allows arbitrary file uploads due to missing authorization, currently awaiting further analysis.

    0000033
    171 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1499 WordPress WP Duplicate Plugin Authenticated Arbitrary File Upload Leading to RCE https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1499

    Post summary

    CVE-2026-1499 is a WordPress WP Duplicate Plugin vulnerability that permits authenticated users to upload arbitrary files, leading to remote code execution.

    0000070
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-1499: WP Duplicate <= 1.1.8 - Authentic... Subscriber-to-RCE in WP Duplicate via chained AJAX+path traversal exploit—first set prod_key_random_id, then bypass auth... https://zerodaysignal.com/vulnerability/CVE-2026-1499 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses CVE-2026-1499 in WP Duplicate, outlining a chained AJAX and path traversal exploit that achieves RCE via authentication bypass, and provides a link to the vulnerability details.

    0000079
    132 followersView on X

Explore more