CVE · Critical

CVE-2018-25095 — Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.3.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-25095 Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.3.0 Improper Control of Generation of Code ('Code Injection') Critical 9.8 < 1.3.0 1.3.0 2023-12-15

CVE-2018-25095

The Duplicator plugin for WordPress through version 1.2.x contains a remote code execution vulnerability in the installer.php file. An unauthenticated attacker can exploit this flaw because the plugin fails to remove the installer.php file after the installation process completes, leaving it accessible on the server. This allows an attacker to execute arbitrary code and compromise the affected WordPress installation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.