Description
WordPress Plugin Page and Post Clone is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Page and Post Clone version 1.1 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that user can edit the specific post being cloned or disable the plugin until a fix is available
References
Related Vulnerabilities
Drupal Core 4.6.x Arbitrary Code Execution (4.6.0 - 4.6.7)
WordPress Plugin Conditional Marketing Mailer for WooCommerce Cross-Site Request Forgery (1.5.2)
WordPress Plugin SupportCandy Arbitrary File Upload (2.0.0)
WordPress Plugin Gravity Forms Salesforce Cross-Site Scripting (1.2.4)
WordPress Plugin Easy Media Download Cross-Site Scripting (1.1.4)