Backup, Restore and Migrate your sites with XCloner <= 4.8.6 - Authenticated (Subscriber+) Information Exposure
medium
The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 4.8.6
- Fixed in:
- 4.8.7
- Disclosed:
- Jun 3, 2026
CVE-2026-48965 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.8.3
unknown
[en] The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.2. This is due to missing or incorrect nonce validation on the Xcloner_Remote_Storage:save() function. This makes it possible for unauthenticated attack...
- Affected:
- up to 4.8.3
- Fixed in:
- 4.8.3
- Disclosed:
- Dec 5, 2025
CVE-2025-11759 on NVD →
Backup, Restore and Migrate your sites with XCloner <= 4.8.2 - Cross-Site Request Forgery in Xcloner_Remote_Storage:save()
medium
The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.2. This is due to missing or incorrect nonce validation on the Xcloner_Remote_Storage:save() function. This makes it possible for unauthenticated attackers t...
- CVSS:
- 4.3
- Affected:
- up to 4.8.2
- Fixed in:
- 4.8.3
- Disclosed:
- Dec 4, 2025
CVE-2025-11759 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.7.4
unknown
[en] The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.7.3. This is due the plugin utilizing sabre without preventing direct access to the files. This makes it possible for unauthenticated attackers...
- Affected:
- up to 4.7.4
- Fixed in:
- 4.7.4
- Disclosed:
- Jul 16, 2024
CVE-2024-6559 on NVD →
XCloner <= 4.7.3 - Unauthenticated Full Path Disclosure
medium
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.7.3. This is due the plugin utilizing sabre without preventing direct access to the files. This makes it possible for unauthenticated attackers to re...
- CVSS:
- 5.3
- Affected:
- up to 4.7.3
- Fixed in:
- 4.7.4
- Disclosed:
- Jul 15, 2024
CVE-2024-6559 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.3.6
unknown
[en] The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.
- Affected:
- up to 4.3.6
- Fixed in:
- 4.3.6
- Disclosed:
- Jun 27, 2022
CVE-2022-0444 on NVD →
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.16 - Unauthenticated Plugin Settings Reset
critical
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.
- CVSS:
- 9.8
- Affected:
- up to 4.2.16
- Fixed in:
- 4.3.6
- Disclosed:
- Jun 6, 2022
CVE-2022-0444 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.2.163
unknown
Authenticated SQL Injection (SQLi) vulnerability discovered by Ngo Van Thien (Sun* Research & Development) WordPress XCloner Backup, Restore and Migrate plugin (versions <= 4.2.161).
- Affected:
- up to 4.2.163
- Fixed in:
- 4.2.163
- Disclosed:
- May 28, 2021
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] >= 4.2.1 - <= 4.2.12
unknown
[en] An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-c...
- Affected:
- 4.2.1 – 4.2.12
- Fixed in:
- 4.2.12
- Disclosed:
- Jan 1, 2021
CVE-2020-35948 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] >= 4.2.1 - <= 4.2.12
unknown
[en] An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).
- Affected:
- 4.2.1 – 4.2.12
- Fixed in:
- 4.2.12
- Disclosed:
- Jan 1, 2021
CVE-2020-35950 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.2.13
unknown
Cross-Site Request Forgery (CSRF) vulnerability discovered by Chloe Chamberland (WordFence) in WordPress XCloner Backup, Restore and Migrate (versions <= 4.2.152).
- Affected:
- up to 4.2.13
- Fixed in:
- 4.2.13
- Disclosed:
- Sep 22, 2020
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.152 - Cross-Site Request Forgery
critical
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).
- CVSS:
- 9.8
- Affected:
- up to 4.2.153
- Fixed in:
- 4.2.153
- Disclosed:
- Aug 18, 2020
CVE-2020-35950 on NVD →
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin 4.2.1 - 4.2.12 - Unprotected AJAX Actions
high
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config...
- CVSS:
- 8.8
- Affected:
- 4.2.1 – 4.2.12
- Fixed in:
- 4.2.153
- Disclosed:
- Aug 18, 2020
CVE-2020-35948 on NVD →
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.4 - Path Traversal to Sensitive Information Disclosure
medium
The XCloner plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.1.4 via leaked directory listings from the 'files_xml.' AJAX action. This can allow authenticated attackers to extract sensitive data including otherwise private filepaths and backups.
- CVSS:
- 4.3
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.5
- Disclosed:
- Dec 31, 2016
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.5
unknown
This plugin is prone to an authenticated path traversal vulnerability. It allows attackers to leverage directory listings to leak otherwise secret file paths to previous backups and acquire full backup contents.
Update the plugin to the latest version.
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
- Disclosed:
- Dec 31, 2016
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.5
unknown
The XCloner plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.1.4 via leaked directory listings from the 'files_xml.' AJAX action. This can allow authenticated attackers to extract sensitive data including otherwise private filepaths and backups.
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
- Disclosed:
- Dec 31, 2016
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.5
unknown
WordPress XCloner Plugin is vulnerable to Cross-Site Request Forgery (CSRF)/File Deletion Vulnerability. There's no nonce check for file deletion, but it you need to be logged in as Administrator to do it.
Update the plugin.
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
- Disclosed:
- Nov 10, 2016
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.3
unknown
[en] cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backup comments feature to create the file.
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- Jun 17, 2015
CVE-2015-4336 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.3
unknown
[en] Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the excl_manual parameter in the xcloner_show page to wpadmin/plugins.php.
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- Jun 17, 2015
CVE-2015-4337 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.3
unknown
[en] Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the language files via a Translation LM_FRONT_* field for a language, as demonstrated by language/italian.php.
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- Jun 17, 2015
CVE-2015-4338 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.2
unknown
[en] The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows local users to obtain sensitive information via the ps command.
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Jun 10, 2015
CVE-2014-8607 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.2
unknown
[en] The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to a backup file in administrators/backups/.
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Jun 10, 2015
CVE-2014-8605 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.2
unknown
[en] The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obtain sensitive information via unspecified vectors.
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Jun 10, 2015
CVE-2014-8604 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.2
unknown
[en] Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the file parameter in a json_return action in the xcloner_show page to wp-admin/admin-ajax.php.
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Jun 10, 2015
CVE-2014-8606 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.2
unknown
[en] cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath], (3) $exclude, (4) $_CONFIG['tarcompress'], (5) $_CONFIG['...
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Jun 10, 2015
CVE-2014-8603 on NVD →
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 - Remote Code Execution
critical
Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the language files via a Translation LM_FRONT_* field for a language, as demonstrated by language/italian.php.
- CVSS:
- 9.8
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- May 10, 2015
CVE-2015-4338 on NVD →
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 - Remote Command Execution
high
cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backup comments feature to create the file.
- CVSS:
- 8.8
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- May 10, 2015
CVE-2015-4336 on NVD →
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the excl_manual parameter in the xcloner_show page to wpadmin/plugins.php.
- CVSS:
- 6.1
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- May 10, 2015
CVE-2015-4337 on NVD →
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Sensitive Information Disclosure
high
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obtain sensitive information via unspecified vectors.
- CVSS:
- 7.5
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Oct 17, 2014
CVE-2014-8604 on NVD →
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Improper Access Control to Information Disclosure
high
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to a backup file in administrators/backups/.
- CVSS:
- 7.5
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.2
- Disclosed:
- Oct 17, 2014
CVE-2014-8605 on NVD →
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Remote Code Execution
high
cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath], (3) $exclude, (4) $_CONFIG['tarcompress'], (5) $_CONFIG['filen...
- CVSS:
- 7.2
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Oct 17, 2014
CVE-2014-8603 on NVD →
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Sensitive Information Disclosure
high
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows local users with administrator privileges to obtain sensitive information via the ps command.
- CVSS:
- 7.2
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Oct 17, 2014
CVE-2014-8607 on NVD →
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Directory Traversal
medium
Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the file parameter in a json_return action in the xcloner_show page to wp-admin/admin-ajax.php.
- CVSS:
- 4.9
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Oct 17, 2014
CVE-2014-8606 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] <= 3.5
unknown
[en] Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password via the config task to index2.php or (2) when the enable_db_backup and sql_mem options are e...
- Affected:
- up to 3.5
- Fixed in:
- 3.5
- Disclosed:
- Apr 25, 2014
CVE-2014-2579 on NVD →
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.0 - Multiple Cross-Site Request Forgery
critical
Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.1.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password via the config task to index2.php or (2) when the enable_db_backup and sql_mem options are enab...
- CVSS:
- 9.6
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- Apr 9, 2014
CVE-2014-2579 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.1
unknown
[en] Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php.
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- Apr 3, 2014
CVE-2014-2340 on NVD →
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.0 - Cross-Site Request Forgery
medium
Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php.
- CVSS:
- 5.4
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- Apr 2, 2014
CVE-2014-2340 on NVD →
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.5
unknown
Authenticated users are able to perform directory listings at any location available to the Wordpress user, leaking filenames of previous backups. This was found in XCloner - Backup and Restore version 3.1.4, but may have been introduced in earlier versions. Attackers can leverage directory listings to leak otherwise s...
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.5
unknown
Update the plugin.
Pluginvulnerabilities discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress XCloner Backup, Restore and Migrate Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerab...
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.2.153
unknown
Update the WordPress XCloner Backup and Restore plugin to the latest available version (at least 4.2.153).
Chloe Chamberland discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress XCloner Backup, Restore and Migrate Plugin. This could allow a malicious actor to force higher privileged...
- Affected:
- up to 4.2.153
- Fixed in:
- 4.2.153
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.5
unknown
Update the plugin to the latest version.
An unknown person discovered and reported this Bypass Vulnerability vulnerability in WordPress XCloner Backup, Restore and Migrate Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has been fixed in versio...
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.2.13
unknown
Update the WordPress XCloner Backup and Restore plugin to the latest available version (at least 4.2.13).
Chloe Chamberland discovered and reported this Broken Access Control vulnerability in WordPress XCloner Backup, Restore and Migrate Plugin. A broken access control issue refers to a missing authorization, authentic...
- Affected:
- up to 4.2.13
- Fixed in:
- 4.2.13