Clone [wp-clone-by-wp-academy] < 2.3.8
unknown
[en] Missing Authorization vulnerability in social share pro Social Share Icons & Social Share Buttons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.5.7.
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.8
- Disclosed:
- Dec 13, 2024
CVE-2023-38514 on NVD →
Clone [wp-clone-by-wp-academy] < 2.3.8
unknown
[en] Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.3.7.
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.8
- Disclosed:
- Dec 9, 2024
CVE-2023-25486 on NVD →
Clone [wp-clone-by-wp-academy] < 2.4.7
unknown
[en] The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the...
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
- Disclosed:
- Nov 20, 2024
CVE-2024-10913 on NVD →
Clone <= 2.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialized_replace'
high
The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vuln...
- CVSS:
- 8.8
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.7
- Disclosed:
- Nov 19, 2024
CVE-2024-10913 on NVD →
Clone [wp-clone-by-wp-academy] < 2.4.6
unknown
[en] Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.6
- Disclosed:
- Nov 1, 2024
CVE-2024-43298 on NVD →
Clone <= 2.4.5 - Missing Authorization
medium
The Clone plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpa_wpc_ajax_install_new() function in versions up to, and including, 2.4.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to install a backup plugin.
- CVSS:
- 4.3
- Affected:
- up to 2.4.5
- Fixed in:
- 2.4.6
- Disclosed:
- Aug 16, 2024
CVE-2024-43298 on NVD →
Inisev Analyst Module <= Various Versions - Missing Authorization
medium
Multiple plugins and/or themes by Inisev for WordPress are vulnerable to unauthorized access due to a missing capability check on several functions in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.4
- Disclosed:
- Apr 10, 2024
CVE-2024-31435 on NVD →
Clone [wp-clone-by-wp-academy] < 2.4.3
unknown
[en] The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.3
- Disclosed:
- Jan 8, 2024
CVE-2023-6750 on NVD →
WP Clone <= 2.4.2 - Sensitive Information Exposure
critical
The Clone plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2. This makes it possible for unauthenticated attackers to download database backups made with the plugin resulting in the potential of a complete site takeover.
- CVSS:
- 9.8
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.3
- Disclosed:
- Dec 18, 2023
CVE-2023-6750 on NVD →
Clone [wp-clone-by-wp-academy] < 2.3.8
unknown
[en] Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permission...
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.8
- Disclosed:
- Jul 28, 2023
CVE-2023-0958 on NVD →
Clone [wp-clone-by-wp-academy] < 2.3.8
unknown
[en] Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attack...
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.8
- Disclosed:
- Jul 28, 2023
CVE-2023-3977 on NVD →
Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function
medium
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers t...
- CVSS:
- 4.3
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.8
- Disclosed:
- Jul 27, 2023
CVE-2023-3977 on NVD →
Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function
medium
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, su...
- CVSS:
- 4.3
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.8
- Disclosed:
- Jul 27, 2023
CVE-2023-0958 on NVD →
Clone <= 2.3.7 - Missing Authorization via wp_ajax_tifm_save_decision
medium
The Clone plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_tifm_save_decision function in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers with subscriber-level access, and above, to modify the 'Test new plug...
- CVSS:
- 4.3
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.8
- Disclosed:
- Mar 8, 2023
CVE-2023-25486 on NVD →
Clone <= 2.3.7 - Cross-Site Request Forgery via wp_ajax_tifm_save_decision
medium
The Clone plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.7. This is due to missing or incorrect nonce validation on the wp_ajax_tifm_save_decision function. This makes it possible for unauthenticated attackers to modify the 'Test new plugins before installing' set...
- CVSS:
- 4.3
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.8
- Disclosed:
- Mar 8, 2023
Clone [wp-clone-by-wp-academy] < 2.1.2
unknown
[en] Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this is might be the sa...
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Mar 28, 2013
CVE-2013-1808 on NVD →
Clone [wp-clone-by-wp-academy] < 2.4.4
unknown
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.4
CVE-2024-31435 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database