CVE-2019-25314

Y

oast Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings parameters. Attackers can inject malicious scripts into title prefix, suffix, menu order, and blacklist fields to execute arbitrary JavaScript in admin interfaces.

Configurations

No configuration.

History

13 Feb 2026, 17:16

Type Values Removed Values Added
References
  • () https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/duplicate-post/yoast-duplicate-post-323-authenticated-admin-stored-cross-site-scripting -
CWE CWE-79
CVSS v2 : unknown
v3 : 6.4
v2 : unknown
v3 : 5.5
Summary (en) Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings parameters. Attackers can inject malicious scripts into title prefix, suffix, menu order, and blacklist fields to execute arbitrary JavaScript in admin interfaces. (en) Yoast Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings parameters. Attackers can inject malicious scripts into title prefix, suffix, menu order, and blacklist fields to execute arbitrary JavaScript in admin interfaces.

11 Feb 2026, 15:27

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 15:16

Updated : 2026-02-13 17:16


NVD link : CVE-2019-25314

Mitre link : CVE-2019-25314

CVE.ORG link : CVE-2019-25314


JSON object : View

Products Affected

No product.

CWE

No CWE.