CVE · Critical

CVE-2018-17207 — Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.2.42

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-17207 Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.2.42 Improper Control of Generation of Code ('Code Injection') Critical 9.8 < 1.2.42 1.2.42 2018-08-29

CVE-2018-17207

The Duplicator plugin before version 1.2.42 leaves installer files (installer.php and installer-backup.php) accessible after backup restoration, which allows attackers to execute arbitrary PHP code by injecting malicious commands into wp-config.php through the database configuration process.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.