{"error":0,"message":null,"data":{"name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More","plugin":"duplicator","link":"https:\/\/wordpress.org\/plugins\/duplicator\/","latest":"1789759440","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"2cdd807004e04b032ac19365442c665de2b09909f3f401c3eec17f264ab344ab","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.3.28","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.28","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-11738","name":"CVE-2020-11738","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-11738","description":"[en] The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ..\/ in the file parameter to duplicator_download or duplicator_init.","date":"2020-04-13"},{"id":"5929e532c42249e519fa9c5c66f8b9f82b087729","name":"Duplicator < 1.3.28 - Directory Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/duplicator-1328-directory-traversal","description":"The Duplicator (Free & Pro) plugin for WordPress is vulnerable to Directory Traversal in versions up to 1.3.28  (and Duplicator Pro before 3.8.7.1) via the 'file' parameter through the duplicator_download() or duplicator_init() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.","date":"2020-02-28"},{"id":"35227c3a-e893-4c68-8cb6-ffe79115fb6d","name":"Duplicator 1.3.24 &amp; 1.3.26 - Unauthenticated Arbitrary File Download","link":"https:\/\/wpscan.com\/vulnerability\/35227c3a-e893-4c68-8cb6-ffe79115fb6d","description":"The issue is being actively exploited, and allows attackers to download arbitrary files, such as the wp-config.php file.\r\n\r\nAccording to the vendor, the vulnerability was only in two versions v1.3.24 and v1.3.26, the vulnerability wasn&#039;t present in versions 1.3.22 and before.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"active","automatable":"yes","technical_impact":"partial","kev":true,"kev_date":"2021-11-03"}}},{"uuid":"71c1c60d8ca5523d21d47cb2fe2ca885f8f6edeb8f4a18c0e848719c45e1c2ea","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.2.33","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.33","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-7543","name":"CVE-2018-7543","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-7543","description":"[en] Cross-site scripting (XSS) vulnerability in installer\/build\/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.","date":"2018-03-26"},{"id":"225a1ca3009b411702c2ead4924fe5cbe69742c6","name":"WordPress Duplicator plugin <=1.2.32 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicator\/vulnerability\/wordpress-duplicator-plugin-1-2-32-cross-site-scripting-xss-vulnerability","description":"Cross-Site Scripting (XSS) vulnerability found in WordPress Duplicator plugin versions <=1.2.32","date":"2018-03-28"},{"id":"0966f187-b44e-4acb-9491-d212d14c3ada","name":"Duplicator &lt;= 1.2.32 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/0966f187-b44e-4acb-9491-d212d14c3ada","description":"The Duplicator &ndash; WordPress Migration Plugin WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null},{"id":"03009301738e204dca874f922704b25c92739d6d","name":"Duplicator <= 1.2.32 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicator\/duplicator-1232-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in installer\/build\/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.","date":"2018-03-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"81d902e3b390b19f812104bd3057711add0819ab7623a806519280e3331a617c","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.2.30","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.30","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-16815","name":"CVE-2017-16815","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-16815","description":"[en] installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values \"url_new\" (\/wp-content\/plugins\/duplicator\/installer\/build\/view.step4.php) and \"logging\" (wp-content\/plugins\/duplicator\/installer\/build\/view.step2.php) are not filtered correctly.","date":"2017-11-14"},{"id":"71b8bf8ea91df281c43193ca2bd7982618111200","name":"WordPress Duplicator plugin <=1.2.28 \u2013 Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicator\/vulnerability\/wordpress-duplicator-plugin-1-2-28-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability found by Ricardo Sanchez in WordPress Duplicator plugin (versions <=1.2.28). The plugin is vulnerable due to incorrectly filtered values \"url_new\" and \"logging\".","date":"2017-11-20"},{"id":"bbd7a36c-4d09-480e-9171-b3a0d76911d3","name":"Duplicator &lt;= 1.2.28 &ndash; Unauthenticated Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/bbd7a36c-4d09-480e-9171-b3a0d76911d3","description":"The Duplicator &ndash; WordPress Migration Plugin WordPress plugin was affected by   security vulnerability.","date":null},{"id":"9ba873441e395c8198a954c974811c638c05410a","name":"Duplicator <= 1.2.28 \u2013 Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicator\/duplicator-1228-unauthenticated-stored-cross-site-scripting","description":"installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values \"url_new\" (\/wp-content\/plugins\/duplicator\/installer\/build\/view.step4.php) and \"logging\" (wp-content\/plugins\/duplicator\/installer\/build\/view.step2.php) are not filtered correctly.","date":"2017-11-07"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"d09960c42d7e133a3a8526050adfe1fd559e3ad7269351b7acf8cc3294f0abb8","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.5.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-9262","name":"CVE-2014-9262","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-9262","description":"[en] The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.","date":"2017-08-07"},{"id":"93d61693-04e2-45db-9d67-60f495c44640","name":"Duplicator 0.5.8 - Privilege Escalation","link":"https:\/\/wpscan.com\/vulnerability\/93d61693-04e2-45db-9d67-60f495c44640","description":"The Duplicator &ndash; WordPress Migration Plugin WordPress plugin was affected by a Privilege Escalation security vulnerability.","date":null},{"id":"87e632e6dbac0ee02d019d9738e6a56962ee01b3","name":"Duplicator < 0.5.10 - Arbitrary Backup Creation and Download","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicator\/duplicator-0510-arbitrary-backup-creation-and-download","description":"The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.","date":"2015-02-19"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"l","a":"n","score":"8.2","severity":"h","exploitable":"3.9","impact":"4.2"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:L\/A:N","score":"8.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"low","a":"none","exploitable":"3.9","impact":"4.2"}}},{"uuid":"e3dc0bfdc2edb219559829d2eb5f82baf86f75a7065d0a378a3a1b387096dd37","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2013-4625","name":"CVE-2013-4625","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2013-4625","description":"[en] Cross-site scripting (XSS) vulnerability in files\/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.","date":"2013-08-09"},{"id":"0f3fc09b-f736-474e-a3e8-37ead77479c1","name":"Duplicator - installer.cleanup.php package Parameter XSS","link":"https:\/\/wpscan.com\/vulnerability\/0f3fc09b-f736-474e-a3e8-37ead77479c1","description":"The Duplicator &ndash; WordPress Migration Plugin WordPress plugin was affected by an installer.cleanup.php package Parameter XSS security vulnerability.","date":null},{"id":"847f99c513bc806a0e2a02810bc40bf9c5b36d17","name":"Duplicator \u2013 WordPress Migration Plugin <= 0.4.4 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicator\/duplicator-wordpress-migration-plugin-044-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in files\/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.","date":"2014-08-01"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"5e0e33d8c2100792b985efc0d145b323be3f1461fc4b7e60b26ebe3a0c9228a7","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.2.42","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.42","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-17207","name":"CVE-2018-17207","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-17207","description":"[en] An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.","date":"2018-09-19"},{"id":"7b0d5800a7b30d64b12595c7fdf9396b27893923","name":"Duplicator <= 1.2.41 - Sensitive Information Disclosure leading to Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicator\/duplicator-1241-sensitive-information-disclosure-leading-to-remote-code-execution","description":"An issue was discovered in Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.","date":"2018-08-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}]}},{"uuid":"d20731202aaac4f6ce9e7b6dbb74961cfd618dea406ef26b7393c2b40903f29d","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.3.28","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.28","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"eacb45a050fae31f53646d9868607d408e61f8b0","name":"WordPress Duplicator plugin <= 1.3.26 - Unauthenticated Arbitrary File Download vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicator\/vulnerability\/wordpress-duplicator-plugin-1-3-26-unauthenticated-arbitrary-file-download-vulnerability","description":"Unauthenticated Arbitrary File Download vulnerability found in the WordPress Duplicator plugin (versions <= 1.3.26).","date":"2020-02-20"}],"impact":[]},{"uuid":"9b1a28490a5cc9477fc1ed8223e560abcba3724d00842c83e5cb0c294fcdcce3","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.2.42","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.42","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8703a62b92afa0ef748aa6a465f4110643003d33","name":"WordPress Duplicator plugin <= 1.2.40 - Arbitrary Code Execution vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicator\/vulnerability\/wordpress-duplicator-plugin-1-2-40-arbitrary-code-execution-vulnerability","description":"Arbitrary Code Execution vulnerability found in WordPress Duplicator plugin (versions <= 1.2.40).","date":"2018-09-05"}],"impact":[]},{"uuid":"9e8f546c3196994fc21f9d76ad0e67101c576f6536dda953fb114b01556c0041","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b5f957e69a0172703bc896d156cd595872ba2a38","name":"WordPress Duplicator Plugin <= 1.1.3 - Cross Site Request Forgery","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicator\/vulnerability\/wordpress-duplicator-plugin-1-1-3-cross-site-request-forgery","description":"This plugin is prone to a cross site request forgery vulnerability.\nUpdate the plugin.","date":"2016-02-11"}],"impact":[]},{"uuid":"f061797f69c7d3f9873c5656b3252b5004c60aadc897223fa3a80678e4bc01f9","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.28","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.5.28","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7a2a23f013e8cd14384aa7e1d552984f215f5cde","name":"WordPress Duplicator  Plugin <= 0.5.26 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicator\/vulnerability\/wordpress-duplicator-plugin-0-5-26-cross-site-scripting","description":"This plugin is prone to a cross site scripting vulnerability via \"logname\" parameter.\nUpdate the plugin.","date":"2015-11-22"}],"impact":[]},{"uuid":"60cdcfefe9915f2208c795e9921b0b6481e1bb5449ed582e224e760277ae63bd","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3847df6b36164b878fde1dfdc9e8d696bd729787","name":"WordPress Duplicator Plugin - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicator\/vulnerability\/wordpress-duplicator-plugin-cross-site-scripting","description":"WordPress Duplicator plugin is prone to a cross-site scripting vulnerability.  It fails to properly clean up user-supplied input.  An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication credentials.  Other attacks are also possible.\nUpdate the plugin.","date":"2013-07-24"}],"impact":[]},{"uuid":"cb9e2047b6fff285028578c909ece8f003db28ad3023d580986226f77cf79cba","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.5.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"057e92715dd30fc2f07dce9f28aaddb76a8f5c48","name":"WordPress Duplicator Plugin <= 0.5.14 - SQL Injection and CSRF","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicator\/vulnerability\/wordpress-duplicator-plugin-0-5-14-sql-injection-and-csrf","description":"Duplicator plugin is prone to an SQL injection and cross-site request forgery vulnerabilities that allow an attacker to get an authenticated admin by executing arbitrary SQL queries.\nUpgrade the plugin.","date":"2015-04-13"}],"impact":[]},{"uuid":"8c9e563494fb8d30458f2fb7ce42e899dc6e035622075a48e4134983018f0d09","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.4.7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2552","name":"CVE-2022-2552","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2552","description":"[en] The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.","date":"2022-08-22"},{"id":"b828262bcee753f004d0c4b4247d3a08c0d962d5","name":"WordPress Duplicator plugin <= 1.4.7 - Unauthenticated System Information Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicator\/vulnerability\/wordpress-duplicator-plugin-1-4-7-unauthenticated-system-information-disclosure-vulnerability","description":"Unauthenticated System Information Disclosure vulnerability discovered by Ihsan Sencan in WordPress Duplicator plugin (versions <= 1.4.7).\nNo patched version available.","date":"2022-08-04"},{"id":"3899b473854b7438f3142076eaf658ac7984f784","name":"Duplicator \u2013 WordPress Migration Plugin <= 1.4.7 - Sensitive Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicator\/duplicator-wordpress-migration-plugin-147-sensitive-information-disclosure","description":"The Duplicator \u2013 WordPress Migration Plugin WordPress plugin is vulnerable to Unauthenticated System Information Disclosure in versions up to, and including, 1.4.7 via the 'view' or 'debug' parameter. This allows an unauthenticated attacker to obtain sensitive configuration information about the vulnerable system which includes details like PHP Version, Operating System, Full Path and more. This requires that the installer script has been run at least once by a site owner\/administrator.","date":"2022-07-27"},{"id":"6b540712-fda5-4be6-ae4b-bd30a9d9d698","name":"Duplicator &lt; 1.4.7.1 - Unauthenticated System Information Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/6b540712-fda5-4be6-ae4b-bd30a9d9d698","description":"The plugin does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-306","name":"Missing Authentication for Critical Function","description":"The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"1bbe0c0ad07130ee6936a7f2b20bfd23967787327d9b19d2c48252eb41039faa","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.4.7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2551","name":"CVE-2022-2551","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2551","description":"[en] The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating.","date":"2022-08-22"},{"id":"fd509d8a9ab8836ec867ba5ee7abbb49db6728ea","name":"WordPress Duplicator plugin <= 1.4.6 - Unauthenticated Backup Download vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicator\/vulnerability\/wordpress-duplicator-plugin-1-4-6-unauthenticated-backup-download-vulnerability","description":"Unauthenticated Backup Download vulnerability discovered by Ihsan Sencan in WordPress Duplicator plugin (versions <= 1.4.6).\nUpdate the WordPress Duplicator plugin to the latest available version (at least 1.4.7).","date":"2022-08-04"},{"id":"9be72bd3bc30d6b62e47c36e3e893b1c483fc5e5","name":"Duplicator \u2013 WordPress Migration Plugin <= 1.4.7 - Unauthenticated Backup Download","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicator\/duplicator-wordpress-migration-plugin-147-unauthenticated-backup-download","description":"The Duplicator WordPress Plugin is vulnerable to Unauthenticated Backup Download in versions up to, and including, 1.4.7 via the 'is_daws' parameter due to the fact that the source code of the response contains the randomized filename related to the back-up file that also exists in the same directory. This makes it possible for an unauthenticated attacker to download a full site backup which may contain sensitive information. This requires that the installer script has been run at least once by a site owner\/administrator.","date":"2022-07-27"},{"id":"f27d753e-861a-4d8d-9b9a-6c99a8a7ebe0","name":"Duplicator &lt; 1.4.7 - Unauthenticated Backup Download","link":"https:\/\/wpscan.com\/vulnerability\/f27d753e-861a-4d8d-9b9a-6c99a8a7ebe0","description":"The plugin discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-425","name":"Direct Request ('Forced Browsing')","description":"The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files."}]}},{"uuid":"1aeefd91840cd185479fb532131db12da7a80c388cd4786b9fe2d2b036eacc7a","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.2.42","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.42","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9e170b72-a46e-4eb6-9441-531a2507f7cc","name":"Duplicator &lt;= 1.2.40 - Unauthenticated Arbitrary Code Execution","link":"https:\/\/wpscan.com\/vulnerability\/9e170b72-a46e-4eb6-9441-531a2507f7cc","description":"If installer files, installer.php and installer-backup.php, are not removed by the administrators, a code injection during the database setup step allows to execute arbitrary code on the server.","date":null}],"impact":[]},{"uuid":"97762e21cceb7ea264921d5cbda89f33db9876c5eda62bdd7e26321211d5cf3f","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3427b434-73c4-4fd6-bca0-681d9f28e988","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/3427b434-73c4-4fd6-bca0-681d9f28e988","description":null,"date":null}],"impact":[]},{"uuid":"c03170ea426aa8922d4eb362adf0cc52cfe6cd5619bdeee69ebc8141d0a35a2f","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.28","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.5.28","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0ab040b4-9ea3-484d-b937-50e0894c3fed","name":"Duplicator &lt;= 0.5.26 - Authenticated Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/0ab040b4-9ea3-484d-b937-50e0894c3fed","description":"The Duplicator &ndash; WordPress Migration Plugin WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"9cd5418ec56b9490cfe5cdd18521c3c7f3c1ee8ada9efd1d6742e402f75766bc","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.5.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"82164d2b-5be8-4cc1-a61e-70038e60b20b","name":"Duplicator &lt;= 0.5.14 - SQL Injection &amp; CSRF","link":"https:\/\/wpscan.com\/vulnerability\/82164d2b-5be8-4cc1-a61e-70038e60b20b","description":"An authorised user with &quot;export&quot; permission or a remote unauthenticated attacker could use this vulnerability to execute arbitrary SQL queries on the victim WordPress web site by enticing an authenticated admin (CSRF).","date":null}],"impact":[]},{"uuid":"44afebf4c6ffe3af5545029ea1f87e6e5c4b0a980e1358d12bf4cb3865ca0656","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"46b6e71d95835c0f33296d2a84e25edb0349a00a","name":"Duplicator < 1.1.4 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicator\/duplicator-114-cross-site-request-forgery","description":"The Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the duplicator_package_build function. This makes it possible for unauthenticated attackers to create and download database and codebase backups via forged request granted they can trick an authenticated user into performing an action such as clicking on a link.","date":"2016-02-09"}],"impact":[]},{"uuid":"9276b2927aaf33daa2aa1dae170b9565b04c10d67570702468beba651b7bbad7","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.28","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.5.28","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6cf301fcf478c63f9b76e61bd98846f6675cd6e8","name":"Duplicator <= 0.5.26 - Authenticated (Admin+) Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicator\/duplicator-0526-authenticated-admin-cross-site-scripting","description":"The Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.5.26 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2015-08-15"}],"impact":[]},{"uuid":"7ded4d0a71f6dc9d184a9e573c393370058b65c2f1bf67dd18df7146fad5b46f","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.5.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fe9ab69d6dd66de7ee293dc7ffb0a53ef7ec7f5d","name":"Duplicator <= 0.5.14 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicator\/duplicator-0514-sql-injection","description":"The Duplicator plugin for WordPress is vulnerable to SQL Injection in versions up to and including 0.5.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2015-04-10"}],"impact":[]},{"uuid":"28db9fc93d2e9024cd28e30dc52f98bdca5bad5fae20cd67c847f165f80d4eb6","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.5.7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6114","name":"CVE-2023-6114","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6114","description":"[en] The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite\/tmp` directory (or the `backups-dup-pro\/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.","date":"2023-12-26"},{"id":"b32e82fce4c4c519863e2a530eef7c9b7d47d2d6","name":"Duplicator <= 1.5.7 AND Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/duplicator-157-and-duplicator-pro-45142-unauthenticated-sensitive-information-exposure","description":"Duplicator and Duplicator Pro for WordPress are vulnerable to Sensitive Information Exposure in various versions. This makes it possible for unauthenticated attackers to download sensitive information\/files leading to the potential for a complete site takeover.","date":"2023-12-04"},{"id":"5c5d41b9-1463-4a9b-862f-e9ee600ef8e1","name":"Duplicator &lt; 1.5.7.1; Duplicator Pro &lt; 4.5.14.2 - Unauthenticated Sensitive Data Exposure","link":"https:\/\/wpscan.com\/vulnerability\/5c5d41b9-1463-4a9b-862f-e9ee600ef8e1","description":"The plugin does not disallow listing the `backups-dup-lite\/tmp` directory (or the `backups-dup-pro\/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."},{"cwe":"CWE-552","name":"Files or Directories Accessible to External Parties","description":"The product makes files or directories accessible to unauthorized actors, even though they should not be."}]}},{"uuid":"c58d1342fb401b93d561d1383f1fa27ab3e439ec39896ab477978d64119f1cba","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.5.7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-51681","name":"CVE-2023-51681","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-51681","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator \u2013 WordPress Migration & Backup Plugin.This issue affects Duplicator \u2013 WordPress Migration & Backup Plugin: from n\/a through 1.5.7.","date":"2024-02-28"},{"id":"c0879f949cc7a32c61b56d866e4d23009d601313","name":"WordPress  Duplicator Plugin  <= 1.5.7 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicator\/vulnerability\/wordpress-duplicator-plugin-1-5-7-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress Duplicator plugin to the latest available version (at least 1.5.7.1).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Duplicator Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 1.5.7.1.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-27"},{"id":"90c0eab6a7827e0ed1883209b16689e776d0afdd","name":"Duplicator <= 1.5.7 - Cross-Site Request Forgery via views\/tools\/diagnostics\/information.php","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicator\/duplicator-157-cross-site-request-forgery-via-viewstoolsdiagnosticsinformationphp","description":"The Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation in the views\/tools\/diagnostics\/information.php file. This makes it possible for unauthenticated attackers to remove some of the plugin's options via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-12-27"},{"id":"c2aca72c-6aa5-4fda-966f-f4f045eda828","name":"Duplicator &lt; 1.5.7.1 - Settings Removal via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/c2aca72c-6aa5-4fda-966f-f4f045eda828","description":"The plugin does not have CSRF checks when remove some of its options, which could allow attackers to make logged in admins perform such action via a CSRF attack","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:N\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"n","a":"h","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:N\/A:H","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"none","a":"high","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0cb0c51e559dc29a16aa07737d5d358389b6a6defb1a5394ba28fbd12365cc85","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.3.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-25095","name":"CVE-2018-25095","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-25095","description":"[en] The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.","date":"2024-01-08"},{"id":"16cc47aa-cb31-4114-b014-7ac5fbc1d3ee","name":"Duplicator &lt; 1.3.0 - Unauthenticated RCE","link":"https:\/\/wpscan.com\/vulnerability\/16cc47aa-cb31-4114-b014-7ac5fbc1d3ee","description":"The plugin does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.","date":null},{"id":"ce988aeeafcdb17ca4988d0d013cc80d6b70a264","name":"Duplicator < 1.3.0 - Unauthenticated Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicator\/duplicator-130-unauthenticated-remote-code-execution","description":"The Duplicator \u2013 WordPress Migration & Backup Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.3.0 (exclusive) via the\/installer.php file. This is due to plugin not properly cleaning up the installer.php file upon completion of the script. This makes it possible for unauthenticated attackers to execute code on the server.","date":"2023-12-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"2ff316f068f55f4495bfd6ea6742e13cb12f281edc2b702486b62abd1310faa7","name":"Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.5.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6210","name":"CVE-2024-6210","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6210","description":"[en] The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use.","date":"2024-07-11"},{"id":"1cd9d020345c6608b0934aa1d44e466f0b9496d3","name":"Duplicator <= 1.5.9 - Full Path Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duplicator\/duplicator-159-full-path-disclosure","description":"The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use.","date":"2024-07-10"},{"id":"a425991c445245d0d291c8612ce02a4e95715ffe","name":"WordPress Duplicator Plugin <= 1.5.9 is vulnerable to Full Path Disclosure (FPD)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duplicator\/vulnerability\/wordpress-duplicator-plugin-1-5-9-full-path-disclosure-vulnerability","description":"<p>WordPress Duplicator Plugin <= 1.5.9 is vulnerable to Full Path Disclosure (FPD)<\/p><p>Software: Duplicator<\/p><p>Link: https:\/\/wordpress.org\/plugins\/duplicator\/#developers<\/p><p>Affected Version <= 1.5.9<\/p><p>Fixed in version 1.5.10 <\/p>","date":"2024-07-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1776153795"}