TGViewer
WebHostMost | The Web Hosting Community WebHostMost | The Web Hosting Community @webhostmost · 449 subscribers
Post #99 134
🚨 VULNERABILITY UPDATE

Critical Auth Bypass in WP Duplicate

A major security flaw, CVE-2026-1499 (CVSS 9.8 - CRITICAL), was disclosed on February 6, 2026, affecting the WP Duplicate plugin (all versions up to 1.1.8).

The Risk: Due to a missing capability check on an AJAX action (process_add_site), attackers can exploit a path traversal flaw to set internal options. This allows an unauthenticated attacker to upload arbitrary files to your server.

The Impact:

Full remote code execution (RCE).

Potential for complete site takeover.

The vulnerability is already being tracked by security researchers as a high-priority threat.

If you use this plugin, update to version 1.1.9 immediately.

Check your wp-content/upload
s for any suspicious .php files or new "Subscriber" accounts you didn't create.

Stay tuned! 🤓

#WordPress #Security #Vulnerability #CVE2026 #WebHostMost
  • 😱 5
  • 🫡 1
More from @webhostmost
  1. May 4, 2026📰 INDUSTRY NEWS AI agents can now buy domains. No human required. On April 15, Cloudflare…
  2. Apr 30, 2026💡 USE CASE Hosting is not just WordPress sites. FragalyseQt is an open-source tool for DN…
  3. Apr 10, 2026🚨 VULNERABILITY UPDATE 🛡 Hackers exploiting Acrobat Reader zero-day flaw since December…
  4. Apr 1, 2026📣 WEBHOSTMOST PROMO Let’s get straight to the data: This is NOT an April Fools joke. 📉 O…
  5. Mar 26, 2026📰 INDUSTRY NEWS The era of the $2.99 shared hosting plan is officially fading. 📉 The 202…
  6. Mar 20, 2026📰 INDUSTRY NEWS Linux MGLRU: +30% Database Performance Boost 🚀 New optimizations for Mul…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →