CVE Database /
CVE-2013-4625
CVE
CVE-2013-4625 — Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 0.4.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2013-4625
|
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 0.4.5 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Unknown
|
< 0.4.5
|
0.4.5 |
2013-08-09 |
—
|
CVE-2013-4625
The Duplicator plugin for WordPress before version 0.4.5 contains a cross-site scripting vulnerability in the files/installer.cleanup.php file that permits attackers to inject malicious scripts or HTML through the package parameter. An attacker could exploit this flaw by crafting a request with specially crafted input to execute arbitrary code in a victim's browser. This vulnerability affects all installations running the plugin prior to the 0.4.5 release.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings