What the vulnerability does
01Description
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.8 via the duplicate_post function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate posts written by other authors including admins. This includes the ability to duplicate password-protected posts, which reveals their contents.
Explanation of Vulnerability in Simple Terms
02Summary
The Ultimate WordPress Toolkit plugin for WordPress contains an authorization flaw affecting versions up to 3.0.8. An authenticated user with low privileges can read and modify sensitive data within the plugin's scope. The vulnerability requires a valid WordPress account but no additional user interaction. Site administrators should update to a version newer than 3.0.8 as soon as possible.
What an attacker can do
03Attacker Capabilities
Read and modify sensitive data in the plugin with a low-privilege WordPress account.
Potential impact on your site
04Site Impact
Any registered user can access and alter plugin data they shouldn't be able to reach.
Conditions required to exploit
05Prerequisites
Attacker must have a valid low-privilege WordPress user account; no user interaction required.
Key dates
06Disclosure timeline
September 4, 2024
CVE published
April 8, 2026
Record updated