A vulnerability has been found in Post Duplicator Plugin up to 3.0.14 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality of the component WordPress Meta API. Performing a manipulation results in deserialization.
This vulnerability is identified as CVE-2026-10749. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.