Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings parameters. Attackers can inject malicious scripts into title prefix, suffix, menu order, and blacklist fields to execute arbitrary JavaScript in admin interfaces.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings parameters. Attackers can inject malicious scripts into title prefix, suffix, menu order, and blacklist fields to execute arbitrary JavaScript in admin interfaces. | |
| Title | Duplicate-Post 3.2.3 - Persistent Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-11T15:59:57.783Z
Reserved: 2026-02-11T14:34:05.768Z
Link: CVE-2019-25314
Updated: 2026-02-11T15:59:53.737Z
Status : Awaiting Analysis
Published: 2026-02-11T15:16:10.263
Modified: 2026-02-11T15:27:26.370
Link: CVE-2019-25314
No data.
OpenCVE Enrichment
No data.