CVE-2026-53739: Yoast Duplicate Post through 4.6 Cross-Site Request Forgery via duplicate_post_dismiss_notice
Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicatepostdismissnotice handler, which verifies no nonce or capability. Attackers can trick any authenticated user into sending a request that sets the duplicatepostshownotice site option, suppressing admin notices network-wide.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Yoast Duplicate Postfrom your environment.Uninstall the Yoast Duplicate Post plugin (or deactivate it) until a security patch is available.
- Compensating control
Restrict access to WordPress administrative interfaces to trusted IP addresses and/or implement network/WAF rules to block unauthorized requests; require re-authentication for sensitive admin actions to reduce risk from forged requests by authenticated users.
- Operational
Inspect the site option named 'duplicate_post_show_notice'; reset it to the intended value if it was changed. Review recent administrative activity and logs for signs of CSRF-driven changes and remediate any unauthorized modifications.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53739?
CVE-2026-53739 has a medium severity rating of 4.3.
How do I fix CVE-2026-53739?
To fix CVE-2026-53739, update the Yoast Duplicate Post plugin to version 4.7 or later.
What type of vulnerability is identified in CVE-2026-53739?
CVE-2026-53739 identifies a cross-site request forgery (CSRF) vulnerability.
What can attackers do with CVE-2026-53739?
Attackers can trick authenticated users into sending requests that can change site options without proper validation.
Which software is affected by CVE-2026-53739?
CVE-2026-53739 affects Yoast Duplicate Post plugin versions through 4.6.