Extension WordPress
Vulnérabilités Backup, Restore and Migrate your sites with XCloner
Cette page rassemble les failles publiées pour Backup, Restore and Migrate your sites with XCloner, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Backup, Restore and Migrate your sites with XCloner
17 fiches
Backup, Restore and Migrate your sites with XCloner <= 4.8.6 – Authenticated (Subscriber+) Information Exposure
The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above,…
*-4.8.6
4.8.7
03/06/2026
Backup, Restore and Migrate your sites with XCloner <= 4.8.2 – Cross-Site Request Forgery in Xcloner_Remote_Storage:save()
The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.2. This is due to missing or incorrect nonce validation on the Xcloner_Remote_Storage:save()…
*-4.8.2
4.8.3
04/12/2025
XCloner <= 4.7.3 – Unauthenticated Full Path Disclosure
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.7.3. This is due the plugin utilizing sabre without preventing direct…
*-4.7.3
4.7.4
15/07/2024
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.16 – Unauthenticated Plugin Settings Reset
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption…
*-4.2.16
4.3.6
06/06/2022
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.152 – Cross-Site Request Forgery
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).
[*, 4.2.153)
4.2.153
18/08/2020
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin 4.2.1 – 4.2.12 – Unprotected AJAX Actions
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code…
4.2.1-4.2.12
4.2.153
18/08/2020
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.4 – Path Traversal to Sensitive Information Disclosure
The XCloner plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.1.4 via leaked directory listings from the 'files_xml.' AJAX action. This can allow authenticated attackers to extract sensitive data including otherwise…
*-3.1.4
3.1.5
31/12/2016
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the excl_manual parameter in the xcloner_show page to wpadmin/plugins.php.
*-3.1.2
3.1.3
10/05/2015
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 – Remote Command Execution
cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backup comments feature to create the file.
*-3.1.2
3.1.3
10/05/2015
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 – Remote Code Execution
Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the language files via a Translation LM_FRONT_* field for a language, as demonstrated by language/italian.php.
[*, 3.1.3)
3.1.3
10/05/2015
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 – Sensitive Information Disclosure
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows local users with administrator privileges to obtain sensitive information via the ps command.
[*, 3.1.2)
3.1.2
17/10/2014
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 – Remote Code Execution
cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath],…
[*, 3.1.2)
3.1.2
17/10/2014
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 – Directory Traversal
Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the file parameter in a json_return action in the xcloner_show page…
[*, 3.1.2)
3.1.2
17/10/2014
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 – Improper Access Control to Information Disclosure
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to…
*-3.1.1
3.1.2
17/10/2014
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 – Sensitive Information Disclosure
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obtain sensitive information via unspecified vectors.
[*, 3.1.2)
3.1.2
17/10/2014
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.0 – Multiple Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.1.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password via the config task to index2.php or (2) when…
[*, 3.1.1)
3.1.1
09/04/2014
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.0 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php.
[*, 3.1.1)
3.1.1
02/04/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.