N/A
2026-04-13< 3.0.11
Post Duplicator <= 3.0.10 - Authenticated (Contributor+) PHP Object Injection
Minimum safe version
3.0.11
Update to 3.0.11 or later to address 10 fixable vulnerabilities
Post Duplicator <= 3.0.10 - Authenticated (Contributor+) PHP Object Injection
Post Duplicator <= 3.0.8 - Missing Authorization to Authenticated (Contributor+) Protected Post Meta Insertion via 'customMetaData' Parameter
CVE-2025-24736
CVE-2024-12472
CVE-2023-49835
CVE-2016-15027
Post Duplicator <= 2.16 - Cross-Site Scripting (XSS)
Post Duplicator <= 2.16 - Reflected Cross-Site Scripting
WordPress Post Duplicator Plugin <= 2.16 - Cross Site Scripting (XSS)
CVE-2021-33852