---
id: CVE-2025-14476
title: >-
  The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is
  vulnerable to PHP Object Injection in all versions up to, and including,
  1.0.46 via deserialization of untrusted input from the content.txt file within
  uploaded Z…
summary: >-
  The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is
  vulnerable to PHP Object Injection in all versions up to, and including,
  1.0.46 via deserialization of untrusted input from the content.txt file within
  uploaded Z…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
published: '2025-12-13'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14476'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/doubly/tags/1.0.46/inc_php/functions.class.php#L1040
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/doubly/tags/1.0.46/inc_php/importer.class.php#L2536
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/doubly/trunk/inc_php/functions.class.php#L1040
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/doubly/trunk/inc_php/importer.class.php#L2536
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3426214/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/4b2c3987-fe7e-426d-8398-acdd6fa3a3dd?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00547
epssPercentile: 0.4401
ingestedAt: '2026-10-07T20:46:46.934Z'
---

## Overview

The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.46 via deserialization of untrusted input from the content.txt file within uploaded ZIP archives. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary code, delete files, retrieve sensitive data, or perform other actions depending on the available gadgets. This is only exploitable by subscribers, when administrators have explicitly enabled that access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
