Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
Severity
5.3MEDIUM
EPSS
51.1%
top 2.12%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedAug 22
Latest updateAug 23

Description

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5unknown/duplicator< 1.4.7

🔴Vulnerability Details

2
GHSA
GHSA-g4pc-gj78-qfjj: The Duplicator WordPress plugin before 12022-08-23
CVEList
Duplicator < 1.4.7.1 - Unauthenticated System Information Disclosure2022-08-22

💥Exploits & PoCs

2
Exploit-DB
WordPress Plugin Duplicator 1.4.7 - Information Disclosure2022-08-01
Nuclei
Duplicator < 1.4.7.1 - Information Disclosure
CVE-2022-2552 (MEDIUM CVSS 5.3) | The Duplicator WordPress plugin bef | cvebase.io