CVE Database /
CVE-2018-25095
CVE · Critical
CVE-2018-25095 — Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.3.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2018-25095
|
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.3.0 |
Improper Control of Generation of Code ('Code Injection') |
Critical
9.8
|
< 1.3.0
|
1.3.0 |
2023-12-15 |
—
|
CVE-2018-25095
The Duplicator plugin for WordPress through version 1.2.x contains a remote code execution vulnerability in the installer.php file. An unauthenticated attacker can exploit this flaw because the plugin fails to remove the installer.php file after the installation process completes, leaving it accessible on the server. This allows an attacker to execute arbitrary code and compromise the affected WordPress installation.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings