CVE-2026-89424

CVE-2026-89424 published: The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authentica...

View full NVD advisory → ← Back to CVE watch