plugin

Xcloner Backup And Restore Vulnerabilities

42 known security issues reported for the Xcloner Backup And Restore WordPress plugin. Most recent disclosed Jun 3, 2026.

4 critical 6 high 7 medium

Running Xcloner Backup And Restore on your site? Check whether your installed version is affected.

Scan your site free

Backup, Restore and Migrate your sites with XCloner <= 4.8.6 - Authenticated (Subscriber+) Information Exposure

medium

The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 4.8.6
Fixed in:
4.8.7
Disclosed:
Jun 3, 2026

CVE-2026-48965 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.8.3

unknown

[en] The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.2. This is due to missing or incorrect nonce validation on the Xcloner_Remote_Storage:save() function. This makes it possible for unauthenticated attack...

Affected:
up to 4.8.3
Fixed in:
4.8.3
Disclosed:
Dec 5, 2025

CVE-2025-11759 on NVD →

Backup, Restore and Migrate your sites with XCloner <= 4.8.2 - Cross-Site Request Forgery in Xcloner_Remote_Storage:save()

medium

The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.2. This is due to missing or incorrect nonce validation on the Xcloner_Remote_Storage:save() function. This makes it possible for unauthenticated attackers t...

CVSS:
4.3
Affected:
up to 4.8.2
Fixed in:
4.8.3
Disclosed:
Dec 4, 2025

CVE-2025-11759 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.7.4

unknown

[en] The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.7.3. This is due the plugin utilizing sabre without preventing direct access to the files. This makes it possible for unauthenticated attackers...

Affected:
up to 4.7.4
Fixed in:
4.7.4
Disclosed:
Jul 16, 2024

CVE-2024-6559 on NVD →

XCloner <= 4.7.3 - Unauthenticated Full Path Disclosure

medium

The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.7.3. This is due the plugin utilizing sabre without preventing direct access to the files. This makes it possible for unauthenticated attackers to re...

CVSS:
5.3
Affected:
up to 4.7.3
Fixed in:
4.7.4
Disclosed:
Jul 15, 2024

CVE-2024-6559 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.3.6

unknown

[en] The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.

Affected:
up to 4.3.6
Fixed in:
4.3.6
Disclosed:
Jun 27, 2022

CVE-2022-0444 on NVD →

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.16 - Unauthenticated Plugin Settings Reset

critical

The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.

CVSS:
9.8
Affected:
up to 4.2.16
Fixed in:
4.3.6
Disclosed:
Jun 6, 2022

CVE-2022-0444 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.2.163

unknown

Authenticated SQL Injection (SQLi) vulnerability discovered by Ngo Van Thien (Sun* Research & Development) WordPress XCloner Backup, Restore and Migrate plugin (versions <= 4.2.161).

Affected:
up to 4.2.163
Fixed in:
4.2.163
Disclosed:
May 28, 2021

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] >= 4.2.1 - <= 4.2.12

unknown

[en] An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-c...

Affected:
4.2.1 – 4.2.12
Fixed in:
4.2.12
Disclosed:
Jan 1, 2021

CVE-2020-35948 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] >= 4.2.1 - <= 4.2.12

unknown

[en] An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).

Affected:
4.2.1 – 4.2.12
Fixed in:
4.2.12
Disclosed:
Jan 1, 2021

CVE-2020-35950 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.2.13

unknown

Cross-Site Request Forgery (CSRF) vulnerability discovered by Chloe Chamberland (WordFence) in WordPress XCloner Backup, Restore and Migrate (versions <= 4.2.152).

Affected:
up to 4.2.13
Fixed in:
4.2.13
Disclosed:
Sep 22, 2020

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.152 - Cross-Site Request Forgery

critical

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).

CVSS:
9.8
Affected:
up to 4.2.153
Fixed in:
4.2.153
Disclosed:
Aug 18, 2020

CVE-2020-35950 on NVD →

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin 4.2.1 - 4.2.12 - Unprotected AJAX Actions

high

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config...

CVSS:
8.8
Affected:
4.2.1 – 4.2.12
Fixed in:
4.2.153
Disclosed:
Aug 18, 2020

CVE-2020-35948 on NVD →

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.4 - Path Traversal to Sensitive Information Disclosure

medium

The XCloner plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.1.4 via leaked directory listings from the 'files_xml.' AJAX action. This can allow authenticated attackers to extract sensitive data including otherwise private filepaths and backups.

CVSS:
4.3
Affected:
up to 3.1.4
Fixed in:
3.1.5
Disclosed:
Dec 31, 2016

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.5

unknown

This plugin is prone to an authenticated path traversal vulnerability. It allows attackers to leverage directory listings to leak otherwise secret file paths to previous backups and acquire full backup contents. Update the plugin to the latest version.

Affected:
up to 3.1.5
Fixed in:
3.1.5
Disclosed:
Dec 31, 2016

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.5

unknown

The XCloner plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.1.4 via leaked directory listings from the 'files_xml.' AJAX action. This can allow authenticated attackers to extract sensitive data including otherwise private filepaths and backups.

Affected:
up to 3.1.5
Fixed in:
3.1.5
Disclosed:
Dec 31, 2016

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.5

unknown

WordPress XCloner Plugin is vulnerable to Cross-Site Request Forgery (CSRF)/File Deletion Vulnerability. There's no nonce check for file deletion, but it you need to be logged in as Administrator to do it. Update the plugin.

Affected:
up to 3.1.5
Fixed in:
3.1.5
Disclosed:
Nov 10, 2016

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.3

unknown

[en] cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backup comments feature to create the file.

Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Jun 17, 2015

CVE-2015-4336 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.3

unknown

[en] Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the excl_manual parameter in the xcloner_show page to wpadmin/plugins.php.

Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Jun 17, 2015

CVE-2015-4337 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.3

unknown

[en] Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the language files via a Translation LM_FRONT_* field for a language, as demonstrated by language/italian.php.

Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Jun 17, 2015

CVE-2015-4338 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.2

unknown

[en] The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows local users to obtain sensitive information via the ps command.

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Jun 10, 2015

CVE-2014-8607 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.2

unknown

[en] The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to a backup file in administrators/backups/.

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Jun 10, 2015

CVE-2014-8605 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.2

unknown

[en] The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obtain sensitive information via unspecified vectors.

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Jun 10, 2015

CVE-2014-8604 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.2

unknown

[en] Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the file parameter in a json_return action in the xcloner_show page to wp-admin/admin-ajax.php.

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Jun 10, 2015

CVE-2014-8606 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.2

unknown

[en] cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath], (3) $exclude, (4) $_CONFIG['tarcompress'], (5) $_CONFIG['...

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Jun 10, 2015

CVE-2014-8603 on NVD →

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 - Remote Code Execution

critical

Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the language files via a Translation LM_FRONT_* field for a language, as demonstrated by language/italian.php.

CVSS:
9.8
Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
May 10, 2015

CVE-2015-4338 on NVD →

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 - Remote Command Execution

high

cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backup comments feature to create the file.

CVSS:
8.8
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
May 10, 2015

CVE-2015-4336 on NVD →

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the excl_manual parameter in the xcloner_show page to wpadmin/plugins.php.

CVSS:
6.1
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
May 10, 2015

CVE-2015-4337 on NVD →

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Sensitive Information Disclosure

high

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS:
7.5
Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Oct 17, 2014

CVE-2014-8604 on NVD →

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Improper Access Control to Information Disclosure

high

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to a backup file in administrators/backups/.

CVSS:
7.5
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
Oct 17, 2014

CVE-2014-8605 on NVD →

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Remote Code Execution

high

cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath], (3) $exclude, (4) $_CONFIG['tarcompress'], (5) $_CONFIG['filen...

CVSS:
7.2
Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Oct 17, 2014

CVE-2014-8603 on NVD →

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Sensitive Information Disclosure

high

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows local users with administrator privileges to obtain sensitive information via the ps command.

CVSS:
7.2
Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Oct 17, 2014

CVE-2014-8607 on NVD →

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Directory Traversal

medium

Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the file parameter in a json_return action in the xcloner_show page to wp-admin/admin-ajax.php.

CVSS:
4.9
Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Oct 17, 2014

CVE-2014-8606 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] <= 3.5

unknown

[en] Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password via the config task to index2.php or (2) when the enable_db_backup and sql_mem options are e...

Affected:
up to 3.5
Fixed in:
3.5
Disclosed:
Apr 25, 2014

CVE-2014-2579 on NVD →

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.0 - Multiple Cross-Site Request Forgery

critical

Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.1.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password via the config task to index2.php or (2) when the enable_db_backup and sql_mem options are enab...

CVSS:
9.6
Affected:
up to 3.1.1
Fixed in:
3.1.1
Disclosed:
Apr 9, 2014

CVE-2014-2579 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.1

unknown

[en] Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php.

Affected:
up to 3.1.1
Fixed in:
3.1.1
Disclosed:
Apr 3, 2014

CVE-2014-2340 on NVD →

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.0 - Cross-Site Request Forgery

medium

Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php.

CVSS:
5.4
Affected:
up to 3.1.1
Fixed in:
3.1.1
Disclosed:
Apr 2, 2014

CVE-2014-2340 on NVD →

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.5

unknown

Authenticated users are able to perform directory listings at any location available to the Wordpress user, leaking filenames of previous backups. This was found in XCloner - Backup and Restore version 3.1.4, but may have been introduced in earlier versions. Attackers can leverage directory listings to leak otherwise s...

Affected:
up to 3.1.5
Fixed in:
3.1.5

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.5

unknown

Update the plugin. Pluginvulnerabilities discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress XCloner Backup, Restore and Migrate Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerab...

Affected:
up to 3.1.5
Fixed in:
3.1.5

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.2.153

unknown

Update the WordPress XCloner Backup and Restore plugin to the latest available version (at least 4.2.153). Chloe Chamberland discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress XCloner Backup, Restore and Migrate Plugin. This could allow a malicious actor to force higher privileged...

Affected:
up to 4.2.153
Fixed in:
4.2.153

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 3.1.5

unknown

Update the plugin to the latest version. An unknown person discovered and reported this Bypass Vulnerability vulnerability in WordPress XCloner Backup, Restore and Migrate Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has been fixed in versio...

Affected:
up to 3.1.5
Fixed in:
3.1.5

Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] < 4.2.13

unknown

Update the WordPress XCloner Backup and Restore plugin to the latest available version (at least 4.2.13). Chloe Chamberland discovered and reported this Broken Access Control vulnerability in WordPress XCloner Backup, Restore and Migrate Plugin. A broken access control issue refers to a missing authorization, authentic...

Affected:
up to 4.2.13
Fixed in:
4.2.13

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database