GHSA-g9w4-m5fx-x3wv

Suggest an improvement
Source
https://github.com/advisories/GHSA-g9w4-m5fx-x3wv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-g9w4-m5fx-x3wv/GHSA-g9w4-m5fx-x3wv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g9w4-m5fx-x3wv
Aliases
  • CVE-2026-1217
Published
2026-03-18T12:31:51Z
Modified
2026-03-19T19:56:20Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
Details

The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and above can use the Rewrite & Republish feature to overwrite any published post with their own content.

Database specific
{
    "cwe_ids":  [
        "CWE-862"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-19T19:37:40Z",
    "nvd_published_at":  "2026-03-18T10:16:23Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / yoast/duplicate-post

Package

Name
yoast/duplicate-post
Purl
pkg:composer/yoast/duplicate-post

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.6

Affected versions

4.*
4.1.2
4.2-RC1
4.2
4.3-RC1
4.3
4.4-RC1
4.4-RC2
4.4-RC3
4.4
4.5-RC1
4.5
4.6-RC1
4.6-RC2

Database specific

last_known_affected_version_range
"<= 4.5"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-g9w4-m5fx-x3wv/GHSA-g9w4-m5fx-x3wv.json"