CVE Database /
CVE-2023-6114
CVE · High
CVE-2023-6114 — Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.5.7.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-6114
|
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.5.7.1 |
Exposure of Sensitive Information to an Unauthorized Actor |
High
7.5
|
< 1.5.7.1
|
1.5.7.1 |
2023-12-04 |
—
|
CVE-2023-6114
The Duplicator plugin before version 1.5.7.1 fails to restrict directory listing for the `backups-dup-lite/tmp` folder where temporary files with sensitive information are stored. If a web server has directory listing enabled, unauthenticated users can browse this directory and access confidential files such as database exports and site archives. This vulnerability exposes complete database dumps and compressed site backups to unauthorized access without requiring authentication.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings