cleantalk
Vulnerabilities and Security Researches

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin, CVE-2014-8604

CVE, Research URL

CVE-2014-8604

Published on
Jun 10, 2015
Research Description
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obtain sensitive information via unspecified vectors.
Affected versions
Min -, max 3.1.2.
Status
vulnerable