← WordPress Vulnerabilities
WordPress security by component

sm page duplicator

sm page duplicator is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 8.1.

Plugin slug: sm-page-duplicator

CVE-2026-16539: Stored page data reaches an SQL query during duplication

sm page duplicator through 1.0.0 uses a stored value in a SQL statement without sanitization or escaping when duplicating a page. An Editor-or-higher user can prepare the stored value and trigger page duplication to alter the query and perform SQL injection. The CNA record does not disclose the stored field, duplication action, query, vulnerable function or obtainable database fields.

PublishedAug 03, 2026
Known safe version> 1.0.0
Published vulnerabilities for sm-page-duplicator
Safe version
Aug 03, 2026 CVE-2026-16539
Stored page data reaches an SQL query during duplication
sm page duplicator through 1.0.0 uses a stored value in a SQL statement without sanitization or escaping when duplicating a page. An Editor-or-higher user can prepare the stored value and trigger page duplication to alter the query and perform SQL injection. The CNA record does not disclose the stored field, duplication action, query, vulnerable function or obtainable database fields.
> 1.0.0
CVE8.1
NVDPending