🚨 VULNERABILITY UPDATE
Critical Auth Bypass in WP Duplicate
A major security flaw, CVE-2026-1499 (CVSS 9.8 - CRITICAL), was disclosed on February 6, 2026, affecting the WP Duplicate plugin (all versions up to 1.1.8).
The Risk: Due to a missing capability check on an AJAX action (process_add_site), attackers can exploit a path traversal flaw to set internal options. This allows an unauthenticated attacker to upload arbitrary files to your server.
The Impact:
Full remote code execution (RCE).
Potential for complete site takeover.
The vulnerability is already being tracked by security researchers as a high-priority threat.
If you use this plugin, update to version 1.1.9 immediately.
Check your wp-content/uploads for any suspicious .php files or new "Subscriber" accounts you didn't create.
Stay tuned! 🤓
#WordPress #Security #Vulnerability #CVE2026 #WebHostMost
Post #99
134
- 😱 5
- 🫡 1