Title: Vulnerability found &#8211; please update!
Last modified: July 31, 2026

---

# Vulnerability found – please update!

 *  Resolved [vkprog](https://wordpress.org/support/users/vkprog/)
 * (@vkprog)
 * [1 week ago](https://wordpress.org/support/topic/vulnerability-found-please-update/)
 * [https://research.cleantalk.org/reports/app/copy-delete-posts#249337](https://research.cleantalk.org/reports/app/copy-delete-posts#249337)
   
   [Duplicate Post # CVE-2026-53738 ](https://research.cleantalk.org/reports/search/copy-delete-posts/CVE-2026-53738)
   CVE, Research URL
 * [CVE-2026-53738](https://wordpress.org/plugins/copy-delete-posts/)Home page URL
 * [Security reports for Duplicate Post](https://wordpress.org/plugins/copy-delete-posts/)
   Application
 * [Duplicate Post](https://research.cleantalk.org/reports/app/copy-delete-posts)
   DateJun 11, 2026Research DescriptionCopy & Delete Posts through 1.5.4 lets any
   plugin-enabled non-admin role invoke every operation in the cdp_action_handling
   AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin
   settings via the f parameter, bypassing per-function capability checks.Affected
   versions
 * max 1.5.4.
 * Status: vulnerable

Viewing 2 replies - 1 through 2 (of 2 total)

 *  Plugin Support [Nick](https://wordpress.org/support/users/d4d5bh6/)
 * (@d4d5bh6)
 * [1 week ago](https://wordpress.org/support/topic/vulnerability-found-please-update/#post-18980578)
 * Thank you for reporting this [@vkprog](https://wordpress.org/support/users/vkprog/),
   we’ll investigate.
 *  Plugin Support [Nick](https://wordpress.org/support/users/d4d5bh6/)
 * (@d4d5bh6)
 * [3 days, 3 hours ago](https://wordpress.org/support/topic/vulnerability-found-please-update/#post-18983962)
 * It’s fixed and released [@vkprog](https://wordpress.org/support/users/vkprog/)

Viewing 2 replies - 1 through 2 (of 2 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fvulnerability-found-please-update%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/copy-delete-posts/assets/icon-128x128.png?rev=2997966)
 * [Duplicate Post](https://wordpress.org/plugins/copy-delete-posts/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/copy-delete-posts/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/copy-delete-posts/)
 * [Active Topics](https://wordpress.org/support/plugin/copy-delete-posts/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/copy-delete-posts/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/copy-delete-posts/reviews/)

## Tags

 * [update](https://wordpress.org/support/topic-tag/update/)

 * 2 replies
 * 2 participants
 * Last reply from: [Nick](https://wordpress.org/support/users/d4d5bh6/)
 * Last activity: [3 days, 3 hours ago](https://wordpress.org/support/topic/vulnerability-found-please-update/#post-18983962)
 * Status: resolved