plugin

Theme File Duplicator Vulnerabilities

4 known security issues reported for the Theme File Duplicator WordPress plugin. Most recent disclosed Apr 17, 2025.

1 high 1 medium

Running Theme File Duplicator on your site? Check whether your installed version is affected.

Scan your site free

Theme File Duplicator [theme-file-duplicator] <= 1.3 (unfixed + closed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rockgod100 Theme File Duplicator allows Path Traversal. This issue affects Theme File Duplicator: from n/a through 1.3.

Affected:
up to 1.3
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-27283 on NVD →

Theme File Duplicator [theme-file-duplicator] <= 1.3 (unfixed + closed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in rockgod100 Theme File Duplicator allows Using Malicious Files. This issue affects Theme File Duplicator: from n/a through 1.3.

Affected:
up to 1.3
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-27282 on NVD →

Theme File Duplicator <= 1.3 - Authenticated (Subscriber+) Arbitrary File Upload

high

The Theme File Duplicator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which...

CVSS:
8.8
Affected:
up to 1.3
Fix:
No patched version reported
Disclosed:
Feb 21, 2025

CVE-2025-27282 on NVD →

Theme File Duplicator <= 1.3 - Authenticated (Subscriber+) Arbitrary File Download

medium

The Theme File Duplicator plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
6.5
Affected:
up to 1.3
Fix:
No patched version reported
Disclosed:
Feb 21, 2025

CVE-2025-27283 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database