plugin

Duplicator Pro Vulnerabilities

6 known security issues reported for the Duplicator Pro WordPress plugin. Most recent disclosed Dec 26, 2023.

1 critical 1 high 1 medium

Running Duplicator Pro on your site? Check whether your installed version is affected.

Scan your site free

Duplicator Pro [duplicator-pro] < 4.5.14.2

unknown

[en] The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in...

Affected:
up to 4.5.14.2
Fixed in:
4.5.14.2
Disclosed:
Dec 26, 2023

CVE-2023-6114 on NVD →

Duplicator <= 1.5.7 AND Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Information Exposure

critical

Duplicator and Duplicator Pro for WordPress are vulnerable to Sensitive Information Exposure in various versions. This makes it possible for unauthenticated attackers to download sensitive information/files leading to the potential for a complete site takeover.

CVSS:
9.8
Affected:
up to 4.5.14.2
Fixed in:
4.5.14.2
Disclosed:
Dec 4, 2023

CVE-2023-6114 on NVD →

Duplicator Pro [duplicator-pro] < 4.5.11.1

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions.

Affected:
up to 4.5.11.1
Fixed in:
4.5.11.1
Disclosed:
May 28, 2023

CVE-2023-33309 on NVD →

Duplicator Pro <= 4.5.11 - Reflected Cross-Site Scripting

medium

The Duplicator Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.5.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...

CVSS:
6.1
Affected:
up to 4.5.11
Fixed in:
4.5.11.1
Disclosed:
May 22, 2023

CVE-2023-33309 on NVD →

Duplicator Pro [duplicator-pro] < 3.8.7.1

unknown

[en] The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.

Affected:
up to 3.8.7.1
Fixed in:
3.8.7.1
Disclosed:
Apr 13, 2020

CVE-2020-11738 on NVD →

Duplicator < 1.3.28 - Directory Traversal

high

The Duplicator (Free & Pro) plugin for WordPress is vulnerable to Directory Traversal in versions up to 1.3.28 (and Duplicator Pro before 3.8.7.1) via the 'file' parameter through the duplicator_download() or duplicator_init() function. This makes it possible for unauthenticated attackers to read the contents of arbit...

CVSS:
7.5
Affected:
up to 3.8.7.1
Fixed in:
3.8.7.1
Disclosed:
Feb 28, 2020

CVE-2020-11738 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database