Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
snapcreek duplicator vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-2551
The Duplicator WordPress plugin prior to 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authe...
Snapcreek Duplicator
NA
CVE-2022-2552
The Duplicator WordPress plugin prior to 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
Snapcreek Duplicator
555
VMScore
CVE-2014-9262
The Duplicator plugin in Wordpress prior to 0.5.10 allows remote authenticated users to create and download backup files.
Snapcreek Duplicator
1 EDB exploit
668
VMScore
CVE-2018-17207
An issue exists in Snap Creek Duplicator prior to 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.
Snapcreek Duplicator
1 Github repository
445
VMScore
CVE-2020-11738
The Snap Creek Duplicator plugin prior to 1.3.28 for WordPress (and Duplicator Pro prior to 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
Snapcreek Duplicator
1 Github repository
NA
CVE-2018-25095
The Duplicator WordPress plugin prior to 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.
Snapcreek Duplicator
1 Github repository
383
VMScore
CVE-2017-16815
installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin prior to 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/dupli...
Snapcreek Duplicator 1.2.28
435
VMScore
CVE-2018-7543
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote malicious users to inject arbitrary JavaScript or HTML via the json parameter.
Snapcreek Duplicator 1.2.32
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started