CVE-2026-19435
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Aug 21, 2026
Vendor
unknown
Description
The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content.