S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
low·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-25075 Scanner

CVE-2021-25075 scanner - Cross-Site Request Forgery (CSRF) vulnerability in Duplicate Page or Post plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-25075
3.5
CVSS

The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings, or perform such attack via CSRF. Furthermore, due to the lack of escaping, this could lead to Stored Cross-Site Scripting issues

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Duplicate Page or Post
AFFECTED< 1.5.1SAFE ✓≥ 1.5.1
Updated Aug 21, 2026View on NVD →
Detail

Duplicate Page or Post is a WordPress plugin that allows users to make copies of existing pages or posts on their WordPress site. This plugin is used primarily to save time when it comes to content creation. Instead of starting from scratch every time, website owners can simply duplicate their existing content and make necessary changes to it. 

However, recently, a major vulnerability was discovered in this plugin. The CVE-2021-25075 vulnerability was found, which significantly affects the security of this plugin. The flaw is related to the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, where any authenticated user can access and modify the plugin's settings, leading to a Cross-Site Scripting (XSS) attack through CSRF. Due to the lack of proper escaping, this vulnerability could result in Stored Cross-Site Scripting issues.

This vulnerability can potentially allow a hacker to take over an entire website or an account hijack. The stored XSS vulnerability exposes the website to the risk of user information leakage, site defacements, unauthorized changes to posts and pages, and even server takeovers. Malicious attackers can easily exploit this flaw since it requires no special privileges or knowledge to make it happen. Once exploited, it can be difficult to repair the damages and potentially lead to financial losses and legal action.

S4E is a powerful security platform that can help website owners identify vulnerabilities and fix them efficiently without requiring any technical expertise. The platform offers several features and tools that are designed to help users scan their websites for vulnerabilities, grants alerts on dangerous issues, and provides customized reports to help users take action against threats. By taking advantage of the comprehensive security features available on the S4E platform, website owners can keep their digital assets safe and secure from potential attacks.

 

REFERENCES

Solution Advice

Protection against this vulnerability can be achieved by following a few simple precautions such as:

  • Update the plugin to its latest version
  • Avoid using the Duplicate Page or Post plugin on public computers or open Wi-Fi connections
  • Disable the plugin if it is not in use
  • Use strong passwords for all user accounts and limit the number of users who have access to the plugin
  • Use a comprehensive security plugin like S4E to scan your website for vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-25075 scanner - Cross-Site Request Forgery (CSRF) vulnerability in Duplicate Page or Post plugin for WordPress | S4E