Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Moderate

CVE-2020-11738

Disclosure Date: April 13, 2020 (last updated February 21, 2025)
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
Attacker Value
Unknown

CVE-2025-24736

Disclosure Date: January 24, 2025 (last updated January 25, 2025)
Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post Duplicator: from n/a through 2.35.
0
Attacker Value
Unknown

CVE-2024-12472

Disclosure Date: January 11, 2025 (last updated January 12, 2025)
The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to by duplicating the post.
Attacker Value
Unknown

CVE-2023-49835

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Duplicator: from n/a through 2.31.
0
Attacker Value
Unknown

CVE-2023-31214

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Arul Prasad J WP Quick Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Quick Post Duplicator: from n/a through 2.0.
0
Attacker Value
Unknown

CVE-2024-6210

Disclosure Date: July 11, 2024 (last updated January 05, 2025)
The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use.
0
Attacker Value
Unknown

CVE-2023-51681

Disclosure Date: February 28, 2024 (last updated February 29, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issue affects Duplicator – WordPress Migration & Backup Plugin: from n/a through 1.5.7.
0
Attacker Value
Unknown

CVE-2024-1368

Disclosure Date: February 28, 2024 (last updated February 12, 2025)
The Page Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the duplicate_dat_page() function in all versions up to, and including, 0.1.1. This makes it possible for unauthenticated attackers to duplicate arbitrary posts and pages.
0
Attacker Value
Unknown

CVE-2018-25095

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.
Attacker Value
Unknown

CVE-2023-6114

Disclosure Date: December 26, 2023 (last updated January 06, 2024)
The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.