CVE-2026-1499

HIGH

WP Duplicate - WordPress Migration Plugin <= 1.1.8 - Authenticated Arbitrary File Upload via Missing Authorization

Title source: llm
STIX 2.1

Description

The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to a missing capability check on the `process_add_site()` AJAX action combined with path traversal in the file upload functionality. This makes it possible for authenticated (subscriber-level) attackers to set the internal `prod_key_random_id` option, which can then be used by an unauthenticated attacker to bypass authentication checks and write arbitrary files to the server via the `handle_upload_single_big_file()` function, ultimately leading to remote code execution.

Scores

CVSS v3 8.8
EPSS 0.0094
EPSS Percentile 56.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (1)
revmakx/WP Duplicate – WordPress Migration Plugin < 1.1.8
Published Feb 06, 2026
Tracked Since Feb 18, 2026