9.8
CVSSv3

CVE-2018-25095

Published: 08/01/2024 Updated: 11/01/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Duplicator WordPress plugin prior to 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.

Vulnerable Product Search on Vulmon Subscribe to Product

snapcreek duplicator

Github Repositories

WordPress - Duplicator < 1.3.0 - Unauthenticated RCE

Duplicator &lt; 130 - Unauthenticated RCE CVE-2018-25095 The plugin does not properly escape values when its installer script replaces values in WordPress configuration files If this installer script is left on the site after use, it could be use to run arbitrary code on the server For more exploits and exclusive ones contact me on telegram @KtN1990 Usage To run this e