CVE · Medium

CVE-2022-2552 — Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.4.7.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2552 Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.4.7.1 Missing Authentication for Critical Function Medium 5.3 < 1.4.7.1 1.4.7.1 2022-07-27

CVE-2022-2552

The Duplicator plugin for WordPress through version 1.4.7 contains an unauthenticated information disclosure vulnerability accessible through the 'view' or 'debug' parameters. An attacker without credentials can retrieve sensitive system details including PHP version, operating system information, and file paths if the plugin's installer script has previously been executed by an administrator. This flaw was patched in version 1.4.7.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.