CVE-2023-4792: Inqsys Duplicate Post Page Menu & Custom Post Type
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplication due to a missing capability check on the duplicate_ppmc_post_as_draft function in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers with subscriber access or higher to duplicate posts and pages.
Affected products
- Inqsys Duplicate Post Page Menu & Custom Post Type: up to and including 2.3.1
Published 2023-09-07. Last modified 2026-06-17.