WordPress security by component
sm page duplicator
Plugin description
sm page duplicator is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 8.1.
Plugin slug:
sm-page-duplicatorLatest vulnerability
CVE-2026-16539: Stored page data reaches an SQL query during duplication
sm page duplicator through 1.0.0 uses a stored value in a SQL statement without sanitization or escaping when duplicating a page. An Editor-or-higher user can prepare the stored value and trigger page duplication to alter the query and perform SQL injection. The CNA record does not disclose the stored field, duplication action, query, vulnerable function or obtainable database fields.
| Safe version |
|
||
|---|---|---|---|
| Aug 03, 2026 |
CVE-2026-16539
Stored page data reaches an SQL query during duplication
sm page duplicator through 1.0.0 uses a stored value in a SQL statement without sanitization or escaping when duplicating a page. An Editor-or-higher user can prepare the stored value and trigger page duplication to alter the query and perform SQL injection. The CNA record does not disclose the stored field, duplication action, query, vulnerable function or obtainable database fields.
|
> 1.0.0 |
CVE8.1
NVDPending
|