Skip to main content

Vendor/product archive

awesomemotive / duplicator CVEs

Beta · best-effort

8 CVEs tagged to awesomemotive / duplicator2 Critical, 4 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2018-25095

Published Jan 8, 2024

The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-6114

Published Dec 26, 2023

The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-33309

Published May 28, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-2552

Published Aug 22, 2022

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and fu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2551

Published Aug 22, 2022

The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer sc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11738

Published Apr 13, 2020

The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or…

CVSS 7.5 · High
evidence mentions
3
Buzz score
46.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2018-17207

Published Sep 19, 2018

An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code int…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-7543

Published Mar 26, 2018

Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary Java…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1