
CVE-2026-19085 The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role… https://www.cve.org/CVERecord?id=CVE-2026-19085
Post summary
The post explains that Duplicate Post WordPress plugin lacks a read‑access check, enabling certain users to duplicate content they shouldn't see, but it provides no PoC, exploit, patch, or evidence of active exploitation.
