cleantalk
Vulnerabilities and Security Researches

Duplicator – WordPress Migration & Backup Plugin, CVE-2018-25095

CVE, Research URL

CVE-2018-25095

Published on
Jan 09, 2024
Research Description
The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.
Affected versions
Min -, max 1.3.0.
Status
vulnerable