6.8
CVSSv2

CVE-2014-2340

Published: 03/04/2014 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the XCloner plugin prior to 3.1.1 for WordPress allows remote malicious users to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php.

Vulnerable Product Search on Vulmon Subscribe to Product

xcloner xcloner

xcloner xcloner 2.1.2

xcloner xcloner 3.0

xcloner xcloner 3.0.3

xcloner xcloner 3.0.1

xcloner xcloner 3.0.6

xcloner xcloner 3.0.8

xcloner xcloner 3.0.7

xcloner xcloner 3.0.5

xcloner xcloner 3.0.2

xcloner xcloner 3.0.4

xcloner xcloner 2.2.1

xcloner xcloner 2.1

Exploits

Advisory ID: HTB23206 Product: XCloner Wordpress plugin Vendor: XCloner Vulnerable Version(s): 310 and probably prior Tested Version: 310 Advisory Publication: March 12, 2014 [without technical details] Vendor Notification: March 12, 2014 Vendor Patch: March 13, 2014 Public Disclosure: April 2, 2014 Vulnerability Type: Cross-Site Request F ...
WordPress XCloner plugin version 310 suffers from a cross site request forgery vulnerability ...