WordPress Duplicate Page or Post plugin before 1.5.1 contains a stored cross-site scripting vulnerability. The plugin does not have any authorization and has a flawed cross-site request forgery check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing unauthenticated users to call it and change the plugin’s settings, or perform such attack via cross-site request forgery.
View the template here CVE-2021-25075.yaml
References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25075