Executive brief
Yoast Duplicate Post is a popular WordPress plugin used to clone posts and pages. A security flaw allows an attacker to trick a logged-in administrator into clicking a link that silently disables important administrative notifications across the entire website. This could be used by attackers to hide other malicious activity or disrupt site management by suppressing critical system alerts.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Yoast Duplicate Post plugin for WordPress through version 4.6. The 'duplicate_post_dismiss_notice' handler fails to implement nonce verification or check for user capabilities. By inducing an authenticated user (typically an administrator) to visit a malicious URL, an attacker can trigger a request that modifies the 'duplicate_post_show_notice' site option. This results in the suppression of administrative notices across the network. The attack requires network connectivity and user interaction but no prior authentication by the attacker.
Affected products
- Yoast Yoast Duplicate Post through 4.6
Timeline
- 2026-06-10: advisory: NVD and VulnCheck published the advisory