plugin

Wp Clone By Wp Academy Vulnerabilities

17 known security issues reported for the Wp Clone By Wp Academy WordPress plugin. Most recent disclosed Dec 13, 2024.

1 critical 1 high 6 medium

Running Wp Clone By Wp Academy on your site? Check whether your installed version is affected.

Scan your site free

Clone [wp-clone-by-wp-academy] < 2.3.8

unknown

[en] Missing Authorization vulnerability in social share pro Social Share Icons & Social Share Buttons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.5.7.

Affected:
up to 2.3.8
Fixed in:
2.3.8
Disclosed:
Dec 13, 2024

CVE-2023-38514 on NVD →

Clone [wp-clone-by-wp-academy] < 2.3.8

unknown

[en] Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.3.7.

Affected:
up to 2.3.8
Fixed in:
2.3.8
Disclosed:
Dec 9, 2024

CVE-2023-25486 on NVD →

Clone [wp-clone-by-wp-academy] < 2.4.7

unknown

[en] The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the...

Affected:
up to 2.4.7
Fixed in:
2.4.7
Disclosed:
Nov 20, 2024

CVE-2024-10913 on NVD →

Clone <= 2.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialized_replace'

high

The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vuln...

CVSS:
8.8
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
Nov 19, 2024

CVE-2024-10913 on NVD →

Clone [wp-clone-by-wp-academy] < 2.4.6

unknown

[en] Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.

Affected:
up to 2.4.6
Fixed in:
2.4.6
Disclosed:
Nov 1, 2024

CVE-2024-43298 on NVD →

Clone <= 2.4.5 - Missing Authorization

medium

The Clone plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpa_wpc_ajax_install_new() function in versions up to, and including, 2.4.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to install a backup plugin.

CVSS:
4.3
Affected:
up to 2.4.5
Fixed in:
2.4.6
Disclosed:
Aug 16, 2024

CVE-2024-43298 on NVD →

Inisev Analyst Module <= Various Versions - Missing Authorization

medium

Multiple plugins and/or themes by Inisev for WordPress are vulnerable to unauthorized access due to a missing capability check on several functions in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.

CVSS:
4.3
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Apr 10, 2024

CVE-2024-31435 on NVD →

Clone [wp-clone-by-wp-academy] < 2.4.3

unknown

[en] The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.

Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Jan 8, 2024

CVE-2023-6750 on NVD →

WP Clone <= 2.4.2 - Sensitive Information Exposure

critical

The Clone plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2. This makes it possible for unauthenticated attackers to download database backups made with the plugin resulting in the potential of a complete site takeover.

CVSS:
9.8
Affected:
up to 2.4.2
Fixed in:
2.4.3
Disclosed:
Dec 18, 2023

CVE-2023-6750 on NVD →

Clone [wp-clone-by-wp-academy] < 2.3.8

unknown

[en] Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permission...

Affected:
up to 2.3.8
Fixed in:
2.3.8
Disclosed:
Jul 28, 2023

CVE-2023-0958 on NVD →

Clone [wp-clone-by-wp-academy] < 2.3.8

unknown

[en] Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attack...

Affected:
up to 2.3.8
Fixed in:
2.3.8
Disclosed:
Jul 28, 2023

CVE-2023-3977 on NVD →

Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function

medium

Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers t...

CVSS:
4.3
Affected:
up to 2.3.7
Fixed in:
2.3.8
Disclosed:
Jul 27, 2023

CVE-2023-3977 on NVD →

Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function

medium

Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, su...

CVSS:
4.3
Affected:
up to 2.3.7
Fixed in:
2.3.8
Disclosed:
Jul 27, 2023

CVE-2023-0958 on NVD →

Clone <= 2.3.7 - Missing Authorization via wp_ajax_tifm_save_decision

medium

The Clone plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_tifm_save_decision function in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers with subscriber-level access, and above, to modify the 'Test new plug...

CVSS:
4.3
Affected:
up to 2.3.7
Fixed in:
2.3.8
Disclosed:
Mar 8, 2023

CVE-2023-25486 on NVD →

Clone <= 2.3.7 - Cross-Site Request Forgery via wp_ajax_tifm_save_decision

medium

The Clone plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.7. This is due to missing or incorrect nonce validation on the wp_ajax_tifm_save_decision function. This makes it possible for unauthenticated attackers to modify the 'Test new plugins before installing' set...

CVSS:
4.3
Affected:
up to 2.3.7
Fixed in:
2.3.8
Disclosed:
Mar 8, 2023

Clone [wp-clone-by-wp-academy] < 2.1.2

unknown

[en] Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this is might be the sa...

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Mar 28, 2013

CVE-2013-1808 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database