CVE-2024-6210
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
Minimum safe version
1.5.10
Update to 1.5.10 or later to address 25 fixable vulnerabilities
CVE-2018-25095
WordPress Duplicator Plugin <= 1.5.7 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-6114
Duplicator <= 0.5.14 - SQL Injection
Duplicator <= 0.5.26 - Authenticated (Admin+) Cross-Site Scripting
Duplicator < 1.1.4 - Cross-Site Request Forgery
Duplicator <= 0.5.14 - SQL Injection & CSRF
Duplicator <= 0.5.26 - Authenticated Cross-Site Scripting (XSS)
wpscan.com
Duplicator <= 1.2.40 - Unauthenticated Arbitrary Code Execution
CVE-2022-2551
CVE-2022-2552
WordPress Duplicator Plugin <= 0.5.14 - SQL Injection and CSRF
WordPress Duplicator Plugin - Cross Site Scripting
WordPress Duplicator Plugin <= 0.5.26 - Cross Site Scripting
WordPress Duplicator Plugin <= 1.1.3 - Cross Site Request Forgery
WordPress Duplicator plugin <= 1.2.40 - Arbitrary Code Execution vulnerability
WordPress Duplicator plugin <= 1.3.26 - Unauthenticated Arbitrary File Download vulnerability
CVE-2018-17207
Duplicator – WordPress Migration Plugin <= 0.4.4 - Cross-Site Scripting
CVE-2014-9262
WordPress Duplicator plugin <=1.2.28 – Stored Cross-Site Scripting (XSS) vulnerability
WordPress Duplicator plugin <=1.2.32 - Cross-Site Scripting (XSS) vulnerability
CVE-2020-11738