CVE-2021-24681
MEDIUM NUCLEIDuplicate Page WP <4.4.2 - XSS
Title source: llmDescription
The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before outputting it, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Nuclei Templates (1)
Duplicate Page WordPress - Stored Cross-Site Scripting
MEDIUMVERIFIEDby theamanrawat
Scores
CVSS v3
4.8
EPSS
0.0030
EPSS Percentile
53.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
duplicatepro/duplicate_page
< 4.4.2
Published
Oct 11, 2021
Tracked Since
Feb 18, 2026