Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
xcloner xcloner vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2020-35950
An issue exists in the XCloner Backup and Restore plugin prior to 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).
Xcloner Xcloner
6.5
CVSSv2
CVE-2015-4336
cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backup comments feature to create the file.
Xcloner Xcloner 3.1.2
3.5
CVSSv2
CVE-2015-4337
Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the excl_manual parameter in the xcloner_show page to wpadmin/plugins.php.
Xcloner Xcloner 3.1.2
6.5
CVSSv2
CVE-2015-4338
Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the language files via a Translation LM_FRONT_* field for a language, as demonstrated by language/italian.php.
Xcloner Xcloner 3.1.2
4.3
CVSSv2
CVE-2022-0444
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin prior to 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated malicious users to reset them, including generating a new backup encryption ke...
Watchful Xcloner
NA
CVE-2014-25791
XCloner Standalone version 3.5 suffers from a cross site request forgery vulnerability.
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2