Unknown Duplicator vulnerabilities
3 known vulnerabilities affecting unknown/duplicator.
Total CVEs
3
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2018-25095CRITICALCVSS 9.8fixed in 1.3.02024-01-08
CVE-2018-25095 [CRITICAL] CWE-94 CVE-2018-25095: The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer scri
The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.
cvelistv5nvd
CVE-2023-6114HIGHCVSS 7.5PoCfixed in 1.5.7.12023-12-26
CVE-2023-6114 [HIGH] CWE-552 CVE-2023-6114: The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does
The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthentica
cvelistv5nvd
CVE-2022-2552MEDIUMCVSS 5.3PoCfixed in 1.4.72022-08-22
CVE-2022-2552 [MEDIUM] CWE-306 CVE-2022-2552: The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before disp
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
cvelistv5nvd