CVE

CVE-2013-4625 — Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 0.4.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2013-4625 Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 0.4.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 0.4.5 0.4.5 2013-08-09

CVE-2013-4625

The Duplicator plugin for WordPress before version 0.4.5 contains a cross-site scripting vulnerability in the files/installer.cleanup.php file that permits attackers to inject malicious scripts or HTML through the package parameter. An attacker could exploit this flaw by crafting a request with specially crafted input to execute arbitrary code in a victim's browser. This vulnerability affects all installations running the plugin prior to the 0.4.5 release.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.