关键漏洞信息 CVE ID: CVE-2026-2301 CVSS Score: 4.3 (Medium) Vulnerability: Missing Authorization Publicly Published: February 24, 2026 Last Updated: February 25, 2026 Affected Software: Post Duplicator Affected Version: <= 3.0.8 Patched Version: 3.0.9 Remediation: Update to version 3.0.9, or a newer patched version Vulnerability Description The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all versions up to, and including, 3.0.8. This is due to the function in using directly to the table instead of WordPress's standard function, which would call to prevent lower-privileged users from setting protected meta keys. References plugins.trac.wordpress.org plugins.trac.wordpress.org plugins.trac.wordpress.org