Junglewise Threat Intelligence

CVE-2026-49046: Arjun Thakur Duplicate Page and Post SQL injection

CVE-2026-49046 · Severity: high · CVSS 8.5 · Published 2026-05-27

Executive brief

The Duplicate Page and Post plugin for WordPress, which allows users to easily clone website content, is vulnerable to a security flaw that could allow an attacker to access the site's database. By exploiting this vulnerability, an attacker could potentially steal sensitive information or disrupt site operations. This issue affects all versions of the plugin up to and including 2.9.5.

Technical details

A Blind SQL Injection vulnerability exists in the Arjun Thakur Duplicate Page and Post plugin for WordPress (versions up to 2.9.5). The flaw stems from improper neutralization of special elements used in an SQL command, allowing an attacker to influence database queries. Exploitation requires 'Contributor' level privileges (PR:L) and is reachable over the network without user interaction. Successful exploitation could allow an attacker to extract sensitive data from the WordPress database. As of the advisory date, no official patch has been released.

Affected products

  • Arjun Thakur Duplicate Page and Post n/a through 2.9.5

Timeline

  • 2026-02-13: other: Reported by researcher timomangcut
  • 2026-05-27: advisory: Published by Patchstack and NVD

References