CVE-2023-4792: Inqsys Duplicate Post Page Menu & Custom Post Type

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplication due to a missing capability check on the duplicate_ppmc_post_as_draft function in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers with subscriber access or higher to duplicate posts and pages.

Affected products

  • Inqsys Duplicate Post Page Menu & Custom Post Type: up to and including 2.3.1

Published 2023-09-07. Last modified 2026-06-17.