CVE-2021-25075 affects the WordPress Duplicate Page or Post plugin prior to version 1.5.1, allowing authenticated users, including subscribers, to modify plugin settings due to missing authorization and a flawed CSRF check. This vulnerability also introduces Stored Cross-Site Scripting (XSS) due to improper escaping. With a CVSS score of 3.5 (Low), the attack requires user interaction and an authenticated user, but can lead to low integrity impact. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist for the XSS aspect, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.1CPE matchmatch criteria | cpe:2.3:a:wpdevart:duplicate_page_or_post:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.