cleantalk
Vulnerabilities and Security Researches

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin, CVE-2022-0444

CVE, Research URL

CVE-2022-0444

Published on
Jun 27, 2022
Research Description
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.
Affected versions
Min -, max 4.2.13.
Status
vulnerable