WordPress security by component
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin
Plugin description
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin backs up, restores, and migrates WordPress sites and databases through configurable cloning tools.
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin (xcloner) is a WordPress plugin with 12 published CVE records in this archive. The latest tracked vulnerability was published Jun 27, 2022; the highest published CVSS base score is 9.9.
Plugin slug:
xclonerLatest vulnerability
CVE-2022-0444: Backup, Restore and Migrate WordPress Sites With the XCloner Plugin: Cross-site request forgery
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
| Safe version |
|
||
|---|---|---|---|
| Jun 27, 2022 |
CVE-2022-0444
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin: Cross-site request forgery
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD4.3
|
| Jan 01, 2021 |
CVE-2020-35950
Xcloner: Cross-site request forgery
Xcloner is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE9.8
NVD8.8
|
| Jan 01, 2021 |
CVE-2020-35948
Xcloner: Code execution
Xcloner is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.9
NVD8.8
|
| Jun 17, 2015 |
CVE-2015-4338
Xcloner: Code execution
Xcloner is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Jun 17, 2015 |
CVE-2015-4337
Xcloner: Cross-site scripting
Xcloner is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD3.5
|
| Jun 17, 2015 |
CVE-2015-4336
Xcloner: A security weakness
Xcloner is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Jun 10, 2015 |
CVE-2014-8607
Xcloner: A security weakness
Xcloner is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD2.1
|
| Jun 10, 2015 |
CVE-2014-8606
Xcloner: Filesystem traversal
Xcloner is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVEPending
NVD4.0
|
| Jun 10, 2015 |
CVE-2014-8605
Xcloner: A security weakness
Xcloner is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.0
|
| Jun 10, 2015 |
CVE-2014-8604
Xcloner: A security weakness
Xcloner is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.0
|
| Jun 10, 2015 |
CVE-2014-8603
Xcloner: A security weakness
Xcloner is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Apr 25, 2014 |
CVE-2014-2579
dbbackup_comp parameter in the generate action to index2.php. NOTE: vector 2 might be a duplicate of CVE-2014-2340, which is for the XCloner: Cross-site request forgery
dbbackup_comp parameter in the generate action to index2.php. NOTE: vector 2 might be a duplicate of CVE-2014-2340, which is for the XCloner is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD7.6
|