CVE-2025-12481
Last modified
CVE-2025-12481 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'saveSettings' function. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'saveSettings' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify plugin settings that control role capabilities, and subsequently exploit the misconfigured capabilities to duplicate and view password-protected posts containing sensitive information.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-12481?
How severe is CVE-2025-12481?
How do I fix CVE-2025-12481?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-12475The Blocksy Companion plugin for WordPress is vulnerable to …6.4
- CVE-2025-12476Resource Lacking AuthN.This issue affects BLU-IC2: through 1…9.8
- CVE-2025-12477Server Version Disclosure.This issue affects BLU-IC2: throug…9.8
- CVE-2025-12478Non-Compliant TLS Configuration.This issue affects BLU-IC2: …9.8
- CVE-2025-12479Systemic Lack of Cross-Site Request Forgery (CSRF) Token Imp…8.8
- CVE-2025-12480Triofox versions prior to 16.7.10368.56560, are vulnerable t…9.1
- CVE-2025-12482The Booking for Appointments and Events Calendar – Amelia pl…7.5
- CVE-2025-12483The Visualizer: Tables and Charts Manager for WordPress plug…6.5
- CVE-2025-12484The Giveaways and Contests by RafflePress – Get More Website…7.2
- CVE-2025-12485Improper privilege management during pre-MFA cookie handling…8.8
- CVE-2025-12486Heimdall Data Database Proxy Cross-Site Scripting Remote Cod…8.8
- CVE-2025-12487oobabooga text-generation-webui trust_remote_code Reliance o…9.8
Are you affected by CVE-2025-12481?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
