Extension WordPress

Vulnérabilités Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

Cette page rassemble les failles publiées pour Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More, leurs plages de versions affectées et les correctifs signalés dans la base locale.

15Vulnérabilités
4Critiques
15Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

15 fiches

CVE-2023-51681 Moyenne · 4,3
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

Duplicator <= 1.5.7 – Cross-Site Request Forgery via views/tools/diagnostics/information.php

The Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation in the views/tools/diagnostics/information.php file. This makes it possible for unauthenticated attackers…

Versions affectées

*-1.5.7

Correctif

1.5.7.1

Publication

27/12/2023

CVE-2018-25095 Critique · 9,8
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

Duplicator < 1.3.0 – Unauthenticated Remote Code Execution

The Duplicator – WordPress Migration & Backup Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.3.0 (exclusive) via the/installer.php file. This is due to plugin not properly cleaning up the installer.php…

Versions affectées

[*, 1.3.0)

Correctif

1.3.0

Publication

15/12/2023

CVE-2023-6114 Critique · 9,8
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

Duplicator <= 1.5.7 AND Duplicator Pro < 4.5.14.2 – Unauthenticated Sensitive Information Exposure

Duplicator and Duplicator Pro for WordPress are vulnerable to Sensitive Information Exposure in various versions. This makes it possible for unauthenticated attackers to download sensitive information/files leading to the potential for a complete site takeover.

Versions affectées

*-1.5.7

Correctif

1.5.7.1

Publication

04/12/2023

CVE-2022-2551 Critique · 9,8
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

Duplicator – WordPress Migration Plugin <= 1.4.7 – Unauthenticated Backup Download

The Duplicator WordPress Plugin is vulnerable to Unauthenticated Backup Download in versions up to, and including, 1.4.7 via the 'is_daws' parameter due to the fact that the source code of the response contains the randomized filename related to…

Versions affectées

*-1.4.7

Correctif

1.4.7.1

Publication

27/07/2022

CVE-2022-2552 Élevée · 7,5
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

Duplicator – WordPress Migration Plugin <= 1.4.7 – Sensitive Information Disclosure

The Duplicator – WordPress Migration Plugin WordPress plugin is vulnerable to Unauthenticated System Information Disclosure in versions up to, and including, 1.4.7 via the 'view' or 'debug' parameter. This allows an unauthenticated attacker to obtain sensitive configuration information…

Versions affectées

*-1.4.7

Correctif

1.4.7.1

Publication

27/07/2022

CVE-2020-11738 Élevée · 7,5
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

Duplicator < 1.3.28 – Directory Traversal

The Duplicator (Free & Pro) plugin for WordPress is vulnerable to Directory Traversal in versions up to 1.3.28 (and Duplicator Pro before 3.8.7.1) via the 'file' parameter through the duplicator_download() or duplicator_init() function. This makes it possible for…

Versions affectées

[*, 1.3.28)

Correctif

1.3.28

Publication

28/02/2020

CVE-2018-17207 Critique · 9,8
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

Duplicator <= 1.2.41 – Sensitive Information Disclosure leading to Remote Code Execution

An issue was discovered in Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.

Versions affectées

*-1.2.40

Correctif

1.2.42

Publication

29/08/2018

CVE-2017-16815 Moyenne · 6,1
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

Duplicator <= 1.2.28 – Unauthenticated Stored Cross-Site Scripting

installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correctly.

Versions affectées

*-1.2.28

Correctif

1.2.30

Publication

07/11/2017

Vulnérabilité Moyenne · 6,5
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

Duplicator < 1.1.4 – Cross-Site Request Forgery

The Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the duplicator_package_build function. This makes it possible for unauthenticated attackers…

Versions affectées

[*, 1.1.4)

Correctif

1.1.4

Publication

09/02/2016

Vulnérabilité Moyenne · 5,5
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

Duplicator <= 0.5.26 – Authenticated (Admin+) Cross-Site Scripting

The Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.5.26 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts that…

Versions affectées

[*, 0.5.28)

Correctif

0.5.28

Publication

15/08/2015

CVE-2013-4625 Moyenne · 6,1
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

Duplicator – WordPress Migration Plugin <= 0.4.4 – Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.

Versions affectées

*-0.4.4

Correctif

0.4.5

Publication

01/08/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités