The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/16cc47aa-cb31-4114-b014-7ac5fbc1d3ee | Exploit Third Party Advisory |
Configurations
History
11 Jan 2024, 18:42
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CPE | cpe:2.3:a:snapcreek:duplicator:*:*:*:*:lite:wordpress:*:* | |
| First Time |
Snapcreek duplicator
Snapcreek |
|
| References | () https://wpscan.com/vulnerability/16cc47aa-cb31-4114-b014-7ac5fbc1d3ee - Exploit, Third Party Advisory | |
| CWE | NVD-CWE-noinfo |
Information
Published : 2024-01-08 19:15
Updated : 2024-01-11 18:42
NVD link : CVE-2018-25095
Mitre link : CVE-2018-25095
CVE.ORG link : CVE-2018-25095
JSON object : View
Products Affected
snapcreek
- duplicator
CWE
