Extension WordPress

Vulnérabilités Backup, Restore and Migrate your sites with XCloner

Cette page rassemble les failles publiées pour Backup, Restore and Migrate your sites with XCloner, leurs plages de versions affectées et les correctifs signalés dans la base locale.

17Vulnérabilités
4Critiques
17Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Backup, Restore and Migrate your sites with XCloner

17 fiches

CVE-2026-48965 Moyenne · 4,3
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate your sites with XCloner <= 4.8.6 – Authenticated (Subscriber+) Information Exposure

The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above,…

Versions affectées

*-4.8.6

Correctif

4.8.7

Publication

03/06/2026

CVE-2025-11759 Moyenne · 4,3
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate your sites with XCloner <= 4.8.2 – Cross-Site Request Forgery in Xcloner_Remote_Storage:save()

The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.2. This is due to missing or incorrect nonce validation on the Xcloner_Remote_Storage:save()…

Versions affectées

*-4.8.2

Correctif

4.8.3

Publication

04/12/2025

CVE-2022-0444 Critique · 9,8
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.16 – Unauthenticated Plugin Settings Reset

The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption…

Versions affectées

*-4.2.16

Correctif

4.3.6

Publication

06/06/2022

CVE-2020-35948 Élevée · 8,8
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin 4.2.1 – 4.2.12 – Unprotected AJAX Actions

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code…

Versions affectées

4.2.1-4.2.12

Correctif

4.2.153

Publication

18/08/2020

Vulnérabilité Moyenne · 4,3
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.4 – Path Traversal to Sensitive Information Disclosure

The XCloner plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.1.4 via leaked directory listings from the 'files_xml.' AJAX action. This can allow authenticated attackers to extract sensitive data including otherwise…

Versions affectées

*-3.1.4

Correctif

3.1.5

Publication

31/12/2016

CVE-2015-4337 Moyenne · 6,1
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 – Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the excl_manual parameter in the xcloner_show page to wpadmin/plugins.php.

Versions affectées

*-3.1.2

Correctif

3.1.3

Publication

10/05/2015

CVE-2015-4336 Élevée · 8,8
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 – Remote Command Execution

cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backup comments feature to create the file.

Versions affectées

*-3.1.2

Correctif

3.1.3

Publication

10/05/2015

CVE-2015-4338 Critique · 9,8
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 – Remote Code Execution

Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the language files via a Translation LM_FRONT_* field for a language, as demonstrated by language/italian.php.

Versions affectées

[*, 3.1.3)

Correctif

3.1.3

Publication

10/05/2015

CVE-2014-8607 Élevée · 7,2
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 – Sensitive Information Disclosure

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows local users with administrator privileges to obtain sensitive information via the ps command.

Versions affectées

[*, 3.1.2)

Correctif

3.1.2

Publication

17/10/2014

CVE-2014-8603 Élevée · 7,2
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 – Remote Code Execution

cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath],…

Versions affectées

[*, 3.1.2)

Correctif

3.1.2

Publication

17/10/2014

CVE-2014-8606 Moyenne · 4,9
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 – Directory Traversal

Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the file parameter in a json_return action in the xcloner_show page…

Versions affectées

[*, 3.1.2)

Correctif

3.1.2

Publication

17/10/2014

CVE-2014-8605 Élevée · 7,5
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 – Improper Access Control to Information Disclosure

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to…

Versions affectées

*-3.1.1

Correctif

3.1.2

Publication

17/10/2014

CVE-2014-8604 Élevée · 7,5
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 – Sensitive Information Disclosure

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obtain sensitive information via unspecified vectors.

Versions affectées

[*, 3.1.2)

Correctif

3.1.2

Publication

17/10/2014

CVE-2014-2579 Critique · 9,6
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.0 – Multiple Cross-Site Request Forgery

Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.1.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password via the config task to index2.php or (2) when…

Versions affectées

[*, 3.1.1)

Correctif

3.1.1

Publication

09/04/2014

CVE-2014-2340 Moyenne · 5,4
Backup, Restore and Migrate your sites with XCloner

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.0 – Cross-Site Request Forgery

Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php.

Versions affectées

[*, 3.1.1)

Correctif

3.1.1

Publication

02/04/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités