CVE · High

CVE-2023-6114 — Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.5.7.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6114 Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More [duplicator] < 1.5.7.1 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 1.5.7.1 1.5.7.1 2023-12-04

CVE-2023-6114

The Duplicator plugin before version 1.5.7.1 fails to restrict directory listing for the `backups-dup-lite/tmp` folder where temporary files with sensitive information are stored. If a web server has directory listing enabled, unauthenticated users can browse this directory and access confidential files such as database exports and site archives. This vulnerability exposes complete database dumps and compressed site backups to unauthorized access without requiring authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.