Plugin Vulnerability Hub
Plugin 13 known issues Latest disclosed Jul 10, 2024

Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More Vulnerabilities

Review known vulnerability records for the WordPress plugin Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More (`duplicator`), including severity, CVE references, affected versions, and patch status.

Known Records
13
High or Critical
6
Linked CVEs
10
Last Updated
Jul 11, 2024
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
13 records include a published patch path.
Severity Mix
3 critical and 3 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2024-6210
Duplicator <= 1.5.9 - Full Path Disclosure

The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilitie...

Published
Jul 10, 2024
Patched Release
1.5.10
Affected Versions
Versions up to 1.5.9
Next Step
Update to 1.5.10 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-51681
Duplicator <= 1.5.7 - Cross-Site Request Forgery via views/tools/diagnostics/information.php

The Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation in the views/tools/diagnostics/information.php file. This makes it possible for unauthenticated attackers...

Published
Dec 27, 2023
Patched Release
1.5.7.1
Affected Versions
Versions up to 1.5.7
Next Step
Update to 1.5.7.1 or newer if supported.
Plugin Critical Patched: Yes CVE-2018-25095
Duplicator < 1.3.0 - Unauthenticated Remote Code Execution

The Duplicator – WordPress Migration & Backup Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.3.0 (exclusive) via the/installer.php file. This is due to plugin not properly cleaning up the installer.php file upon completion of the script...

Published
Dec 15, 2023
Patched Release
1.3.0
Affected Versions
Versions before 1.3.0
Next Step
Update to 1.3.0 or newer if supported.
Plugin Critical Patched: Yes CVE-2022-2551
Duplicator – WordPress Migration Plugin <= 1.4.7 - Unauthenticated Backup Download

The Duplicator WordPress Plugin is vulnerable to Unauthenticated Backup Download in versions up to, and including, 1.4.7 via the 'is_daws' parameter due to the fact that the source code of the response contains the randomized filename related to the back-up file that also exists...

Published
Jul 27, 2022
Patched Release
1.4.7.1
Affected Versions
Versions up to 1.4.7
Next Step
Update to 1.4.7.1 or newer if supported.
Plugin High Patched: Yes CVE-2022-2552
Duplicator – WordPress Migration Plugin <= 1.4.7 - Sensitive Information Disclosure

The Duplicator – WordPress Migration Plugin WordPress plugin is vulnerable to Unauthenticated System Information Disclosure in versions up to, and including, 1.4.7 via the 'view' or 'debug' parameter. This allows an unauthenticated attacker to obtain sensitive configuration infor...

Published
Jul 27, 2022
Patched Release
1.4.7.1
Affected Versions
Versions up to 1.4.7
Next Step
Update to 1.4.7.1 or newer if supported.
Plugin Critical Patched: Yes CVE-2018-17207
Duplicator <= 1.2.41 - Sensitive Information Disclosure leading to Remote Code Execution

An issue was discovered in Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.

Published
Aug 29, 2018
Patched Release
1.2.42
Affected Versions
Versions up to 1.2.40
Next Step
Update to 1.2.42 or newer if supported.
Plugin Medium Patched: Yes CVE-2018-7543
Duplicator <= 1.2.32 - Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.

Published
Mar 15, 2018
Patched Release
1.2.33
Affected Versions
Versions up to 1.2.32
Next Step
Update to 1.2.33 or newer if supported.
Plugin Medium Patched: Yes CVE-2017-16815
Duplicator <= 1.2.28 – Unauthenticated Stored Cross-Site Scripting

installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view...

Published
Nov 07, 2017
Patched Release
1.2.30
Affected Versions
Versions up to 1.2.28
Next Step
Update to 1.2.30 or newer if supported.
Plugin Medium Patched: Yes
Duplicator < 1.1.4 - Cross-Site Request Forgery

The Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the duplicator_package_build function. This makes it possible for unauthenticated attackers to create a...

Published
Feb 09, 2016
Patched Release
1.1.4
Affected Versions
Versions before 1.1.4
Next Step
Update to 1.1.4 or newer if supported.
Plugin Medium Patched: Yes
Duplicator <= 0.5.26 - Authenticated (Admin+) Cross-Site Scripting

The Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.5.26 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts that execute in...

Published
Aug 15, 2015
Patched Release
0.5.28
Affected Versions
Versions before 0.5.28
Next Step
Update to 0.5.28 or newer if supported.
Plugin High Patched: Yes
Duplicator <= 0.5.14 - SQL Injection

The Duplicator plugin for WordPress is vulnerable to SQL Injection in versions up to and including 0.5.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append addit...

Published
Apr 10, 2015
Patched Release
0.5.16
Affected Versions
Versions up to 0.5.14
Next Step
Update to 0.5.16 or newer if supported.
Plugin High Patched: Yes CVE-2014-9262
Duplicator < 0.5.10 - Arbitrary Backup Creation and Download

The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.

Published
Feb 19, 2015
Patched Release
0.5.10
Affected Versions
Versions before 0.5.10
Next Step
Update to 0.5.10 or newer if supported.