Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
snapcreek duplicator vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2018-25095
The Duplicator WordPress plugin prior to 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.
Snapcreek Duplicator
1 Github repository
7.5
CVSSv3
CVE-2022-2551
The Duplicator WordPress plugin prior to 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authe...
Snapcreek Duplicator
5.3
CVSSv3
CVE-2022-2552
The Duplicator WordPress plugin prior to 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
Snapcreek Duplicator
7.5
CVSSv3
CVE-2020-11738
The Snap Creek Duplicator plugin prior to 1.3.28 for WordPress (and Duplicator Pro prior to 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
Snapcreek Duplicator
1 Github repository
9.8
CVSSv3
CVE-2018-17207
An issue exists in Snap Creek Duplicator prior to 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.
Snapcreek Duplicator
1 Github repository
6.1
CVSSv3
CVE-2018-7543
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote malicious users to inject arbitrary JavaScript or HTML via the json parameter.
Snapcreek Duplicator 1.2.32
1 EDB exploit
6.1
CVSSv3
CVE-2017-16815
installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin prior to 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/dupli...
Snapcreek Duplicator 1.2.28
8.2
CVSSv3
CVE-2014-9262
The Duplicator plugin in Wordpress prior to 0.5.10 allows remote authenticated users to create and download backup files.
Snapcreek Duplicator
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started