VendorsAwesome Motiveduplicatorall versions
Vulnerabilities

Awesome Motive Inc. Duplicator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2018-17207
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.
Published 2018-09-19 · Modified
9.8EPSS 0.601
CVE-2018-25095
Duplicator < 1.3.0 - Unauthenticated RCE
Published 2024-01-08 · Modified
9.8EPSS 0.009
CVE-2020-11738
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
Published 2020-04-13 · Analyzed
7.5KEV1 PoCEPSS 0.978
CVE-2023-6114
Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure
Published 2023-12-26 · Modified
7.5EPSS 0.309
CVE-2022-2551
Duplicator < 1.4.7 - Unauthenticated Backup Download
Published 2022-08-22 · Modified
7.51 PoCEPSS 0.167
CVE-2023-33309
WordPress Duplicator Pro Plugin <= 4.5.11 is vulnerable to Cross Site Scripting (XSS)
Published 2023-05-28 · Modified
7.1EPSS 0.004
CVE-2018-7543
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.
Published 2018-03-26 · Modified
6.11 PoCEPSS 0.033
CVE-2022-2552
Duplicator < 1.4.7.1 - Unauthenticated System Information Disclosure
Published 2022-08-22 · Modified
5.31 PoCEPSS 0.113