CVE · High

CVE-2022-2551 — Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.4.7.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2551 Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.4.7.1 Direct Request ('Forced Browsing') High 7.5 < 1.4.7.1 1.4.7.1 2022-07-27

CVE-2022-2551

The Duplicator plugin versions up to and including 1.4.7 allows unauthenticated attackers to download complete site backups through the 'is_daws' parameter, which exposes the randomized backup filename in the response code. An attacker can use this disclosed filename to retrieve the backup file from the same directory, potentially accessing sensitive data contained within. This vulnerability is exploitable only if the plugin's installer script has been executed previously by a site administrator, and the issue was fixed in version 1.4.7.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.