← WordPress Vulnerabilities
WordPress security by component

Duplicator

Duplicator is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Jul 11, 2024; the highest CVE/CNA score is 9.8.

Plugin slug: duplicator

CVE-2024-6210: Duplicator: A security weakness

Duplicator is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJul 11, 2024
Safe version guidanceSee mitigation notes
Safe version
Jul 11, 2024 CVE-2024-6210
Duplicator: A security weakness
Duplicator is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Feb 28, 2024 CVE-2023-51681
Duplicator – WordPress Migration & Backup Plugin: Cross-site request forgery
Duplicator – WordPress Migration & Backup Plugin is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVDPending
Jan 08, 2024 CVE-2018-25095
Duplicator: A security weakness
Duplicator is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Dec 26, 2023 CVE-2023-6114
Duplicator: A security weakness
Duplicator is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Aug 22, 2022 CVE-2022-2552
Duplicator: A security weakness
Duplicator is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Aug 22, 2022 CVE-2022-2551
Duplicator: A security weakness
Duplicator is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Apr 13, 2020 CVE-2020-11738
Duplicator: Filesystem traversal
Duplicator is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVD7.5
Sep 19, 2018 CVE-2018-17207
Duplicator: Code execution
Duplicator is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVD9.8
Mar 26, 2018 CVE-2018-7543
Duplicator: Cross-site scripting
Duplicator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Nov 14, 2017 CVE-2017-16815
Duplicator: Cross-site scripting
Duplicator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 07, 2017 CVE-2014-9262
Duplicator: A security weakness
Duplicator is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.2
NVD8.2
Aug 09, 2013 CVE-2013-4625
Duplicator: Cross-site scripting
Duplicator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3