Junglewise Threat Intelligence

CVE-2026-39474: Metaphor Creations Post Duplicator PHP Object Injection

CVE-2026-39474 · Severity: high · CVSS 8.8 · Published 2026-06-15

Technologies: Metaphor Creations Post Duplicator. Vendors: Metaphor Creations.

Executive brief

Post Duplicator, a WordPress plugin used to clone posts and pages, contains a security flaw that allows users with 'Contributor' level access to execute unauthorized actions. By exploiting this vulnerability, an attacker could potentially take control of the website, access sensitive data, or disrupt site operations. This is particularly concerning for sites that allow multiple users to create content, as it elevates the risk of a complete site compromise.

Technical details

The Post Duplicator plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 3.0.10. This issue stems from the insecure deserialization of user-supplied input (CWE-502) provided by an authenticated user with Contributor-level permissions or higher. An attacker can exploit this by submitting a specially crafted PHP serialized string, which, if a suitable Property-Oriented Programming (POP) chain is present in the environment, could lead to remote code execution, file deletion, or unauthorized database access. The vulnerability is resolved in version 3.0.11.

Affected products

  • Metaphor Creations Post Duplicator <= 3.0.10

Timeline

  • 2026-01-28: other: Reported by Nguyen Ba Khanh
  • 2026-04-13: advisory: Initial advisory published by Patchstack
  • 2026-04-13: patched: Version 3.0.11 released to address the vulnerability
  • 2026-06-15: disclosed: CVE published to NVD

References

Related threats