plugin

Duplicator Vulnerabilities

40 known security issues reported for the Duplicator WordPress plugin. Most recent disclosed Jul 11, 2024.

4 critical 4 high 7 medium

Running Duplicator on your site? Check whether your installed version is affected.

Scan your site free

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.5.10

unknown

[en] The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance wor...

Affected:
up to 1.5.10
Fixed in:
1.5.10
Disclosed:
Jul 11, 2024

CVE-2024-6210 on NVD →

Duplicator <= 1.5.9 - Full Path Disclosure

medium

The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On...

CVSS:
5.3
Affected:
up to 1.5.9
Fixed in:
1.5.10
Disclosed:
Jul 10, 2024

CVE-2024-6210 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.5.7.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issue affects Duplicator – WordPress Migration & Backup Plugin: from n/a through 1.5.7.

Affected:
up to 1.5.7.1
Fixed in:
1.5.7.1
Disclosed:
Feb 28, 2024

CVE-2023-51681 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.3.0

unknown

[en] The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.

Affected:
up to 1.3.0
Fixed in:
1.3.0
Disclosed:
Jan 8, 2024

CVE-2018-25095 on NVD →

Duplicator <= 1.5.7 - Cross-Site Request Forgery via views/tools/diagnostics/information.php

medium

The Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation in the views/tools/diagnostics/information.php file. This makes it possible for unauthenticated attackers to remove some of the plugin's options v...

CVSS:
4.3
Affected:
up to 1.5.7
Fixed in:
1.5.7.1
Disclosed:
Dec 27, 2023

CVE-2023-51681 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.5.7.1

unknown

[en] The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in...

Affected:
up to 1.5.7.1
Fixed in:
1.5.7.1
Disclosed:
Dec 26, 2023

CVE-2023-6114 on NVD →

Duplicator < 1.3.0 - Unauthenticated Remote Code Execution

critical

The Duplicator – WordPress Migration & Backup Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.3.0 (exclusive) via the/installer.php file. This is due to plugin not properly cleaning up the installer.php file upon completion of the script. This makes it possible for unauthentic...

CVSS:
9.8
Affected:
up to 1.3.0
Fixed in:
1.3.0
Disclosed:
Dec 15, 2023

CVE-2018-25095 on NVD →

Duplicator <= 1.5.7 AND Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Information Exposure

critical

Duplicator and Duplicator Pro for WordPress are vulnerable to Sensitive Information Exposure in various versions. This makes it possible for unauthenticated attackers to download sensitive information/files leading to the potential for a complete site takeover.

CVSS:
9.8
Affected:
up to 1.5.7
Fixed in:
1.5.7.1
Disclosed:
Dec 4, 2023

CVE-2023-6114 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.4.7.1

unknown

[en] The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating.

Affected:
up to 1.4.7.1
Fixed in:
1.4.7.1
Disclosed:
Aug 22, 2022

CVE-2022-2551 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.4.7.1

unknown

[en] The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.

Affected:
up to 1.4.7.1
Fixed in:
1.4.7.1
Disclosed:
Aug 22, 2022

CVE-2022-2552 on NVD →

Duplicator – WordPress Migration Plugin <= 1.4.7 - Unauthenticated Backup Download

critical

The Duplicator WordPress Plugin is vulnerable to Unauthenticated Backup Download in versions up to, and including, 1.4.7 via the 'is_daws' parameter due to the fact that the source code of the response contains the randomized filename related to the back-up file that also exists in the same directory. This makes it pos...

CVSS:
9.8
Affected:
up to 1.4.7
Fixed in:
1.4.7.1
Disclosed:
Jul 27, 2022

CVE-2022-2551 on NVD →

Duplicator – WordPress Migration Plugin <= 1.4.7 - Sensitive Information Disclosure

high

The Duplicator – WordPress Migration Plugin WordPress plugin is vulnerable to Unauthenticated System Information Disclosure in versions up to, and including, 1.4.7 via the 'view' or 'debug' parameter. This allows an unauthenticated attacker to obtain sensitive configuration information about the vulnerable system which...

CVSS:
7.5
Affected:
up to 1.4.7
Fixed in:
1.4.7.1
Disclosed:
Jul 27, 2022

CVE-2022-2552 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.3.28

unknown

[en] The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.

Affected:
up to 1.3.28
Fixed in:
1.3.28
Disclosed:
Apr 13, 2020

CVE-2020-11738 on NVD →

Duplicator < 1.3.28 - Directory Traversal

high

The Duplicator (Free & Pro) plugin for WordPress is vulnerable to Directory Traversal in versions up to 1.3.28 (and Duplicator Pro before 3.8.7.1) via the 'file' parameter through the duplicator_download() or duplicator_init() function. This makes it possible for unauthenticated attackers to read the contents of arbit...

CVSS:
7.5
Affected:
up to 1.3.28
Fixed in:
1.3.28
Disclosed:
Feb 28, 2020

CVE-2020-11738 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.3.28

unknown

Unauthenticated Arbitrary File Download vulnerability found in the WordPress Duplicator plugin (versions <= 1.3.26).

Affected:
up to 1.3.28
Fixed in:
1.3.28
Disclosed:
Feb 20, 2020

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.2.42

unknown

[en] An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.

Affected:
up to 1.2.42
Fixed in:
1.2.42
Disclosed:
Sep 19, 2018

CVE-2018-17207 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.2.42

unknown

Arbitrary Code Execution vulnerability found in WordPress Duplicator plugin (versions <= 1.2.40).

Affected:
up to 1.2.42
Fixed in:
1.2.42
Disclosed:
Sep 5, 2018

Duplicator <= 1.2.41 - Sensitive Information Disclosure leading to Remote Code Execution

critical

An issue was discovered in Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.

CVSS:
9.8
Affected:
up to 1.2.40
Fixed in:
1.2.42
Disclosed:
Aug 29, 2018

CVE-2018-17207 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.2.33

unknown

[en] Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.

Affected:
up to 1.2.33
Fixed in:
1.2.33
Disclosed:
Mar 26, 2018

CVE-2018-7543 on NVD →

Duplicator <= 1.2.32 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.

CVSS:
6.1
Affected:
up to 1.2.32
Fixed in:
1.2.33
Disclosed:
Mar 15, 2018

CVE-2018-7543 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.2.30

unknown

[en] installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correc...

Affected:
up to 1.2.30
Fixed in:
1.2.30
Disclosed:
Nov 14, 2017

CVE-2017-16815 on NVD →

Duplicator <= 1.2.28 – Unauthenticated Stored Cross-Site Scripting

medium

installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correctly.

CVSS:
6.1
Affected:
up to 1.2.28
Fixed in:
1.2.30
Disclosed:
Nov 7, 2017

CVE-2017-16815 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.10

unknown

[en] The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.

Affected:
up to 0.5.10
Fixed in:
0.5.10
Disclosed:
Aug 7, 2017

CVE-2014-9262 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.1.4

unknown

This plugin is prone to a cross site request forgery vulnerability. Update the plugin.

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 11, 2016

Duplicator < 1.1.4 - Cross-Site Request Forgery

medium

The Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the duplicator_package_build function. This makes it possible for unauthenticated attackers to create and download database and codebase backup...

CVSS:
6.5
Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 9, 2016

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.1.4

unknown

The Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the duplicator_package_build function. This makes it possible for unauthenticated attackers to create and download database and codebase backup...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 9, 2016

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.28

unknown

This plugin is prone to a cross site scripting vulnerability via "logname" parameter. Update the plugin.

Affected:
up to 0.5.28
Fixed in:
0.5.28
Disclosed:
Nov 22, 2015

Duplicator <= 0.5.26 - Authenticated (Admin+) Cross-Site Scripting

medium

The Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.5.26 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
5.5
Affected:
up to 0.5.28
Fixed in:
0.5.28
Disclosed:
Aug 15, 2015

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.28

unknown

The Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.5.26 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 0.5.28
Fixed in:
0.5.28
Disclosed:
Aug 15, 2015

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.15

unknown

Duplicator plugin is prone to an SQL injection and cross-site request forgery vulnerabilities that allow an attacker to get an authenticated admin by executing arbitrary SQL queries. Upgrade the plugin.

Affected:
up to 0.5.15
Fixed in:
0.5.15
Disclosed:
Apr 13, 2015

Duplicator <= 0.5.14 - SQL Injection

high

The Duplicator plugin for WordPress is vulnerable to SQL Injection in versions up to and including 0.5.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL queries into already existing...

CVSS:
8.8
Affected:
up to 0.5.14
Fixed in:
0.5.16
Disclosed:
Apr 10, 2015

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.16

unknown

The Duplicator plugin for WordPress is vulnerable to SQL Injection in versions up to and including 0.5.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL queries into already existing...

Affected:
up to 0.5.16
Fixed in:
0.5.16
Disclosed:
Apr 10, 2015

Duplicator < 0.5.10 - Arbitrary Backup Creation and Download

high

The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.

CVSS:
8.2
Affected:
up to 0.5.10
Fixed in:
0.5.10
Disclosed:
Feb 19, 2015

CVE-2014-9262 on NVD →

Duplicator – WordPress Migration Plugin <= 0.4.4 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.

CVSS:
6.1
Affected:
up to 0.4.4
Fixed in:
0.4.5
Disclosed:
Aug 1, 2014

CVE-2013-4625 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.4.5

unknown

[en] Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.

Affected:
up to 0.4.5
Fixed in:
0.4.5
Disclosed:
Aug 9, 2013

CVE-2013-4625 on NVD →

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.4.5

unknown

WordPress Duplicator plugin is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication credentials. Oth...

Affected:
up to 0.4.5
Fixed in:
0.4.5
Disclosed:
Jul 24, 2013

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.2.42

unknown

If installer files, installer.php and installer-backup.php, are not removed by the administrators, a code injection during the database setup step allows to execute arbitrary code on the server.

Affected:
up to 1.2.42
Fixed in:
1.2.42

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 1.1.4

unknown
Affected:
up to 1.1.4
Fixed in:
1.1.4

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.28

unknown

The Duplicator &ndash; WordPress Migration Plugin WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 0.5.28
Fixed in:
0.5.28

Duplicator &#8211; Backups &amp; Migration Plugin &#8211; Cloud Backups, Scheduled Backups, &amp; More [duplicator] < 0.5.16

unknown

An authorised user with &quot;export&quot; permission or a remote unauthenticated attacker could use this vulnerability to execute arbitrary SQL queries on the victim WordPress web site by enticing an authenticated admin (CSRF).

Affected:
up to 0.5.16
Fixed in:
0.5.16

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database