vendor:
Duplicator
by:
Dmitrii Ignatyev
6.1
CVSS
HIGH
Sensitive Data Exposure
200
CWE
Product Name: Duplicator
Affected Version From: 1.5.7.1
Affected Version To: 1.5.7.1
Patch Exists: YES
Related CWE: CVE-2023-6114
CPE: a:wordpress:duplicator:1.5.7.1
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=154964, https://www.infosecmatter.com/nessus-plugin-library/?id=139377, https://www.infosecmatter.com/nessus-plugin-library/?id=148307, https://www.infosecmatter.com/nessus-plugin-library/?id=81402, https://www.infosecmatter.com/nessus-plugin-library/?id=81378, https://www.infosecmatter.com/nessus-plugin-library/?id=81821, https://www.infosecmatter.com/nessus-plugin-library/?id=157290, https://www.infosecmatter.com/nessus-plugin-library/?id=71218, https://www.infosecmatter.com/nessus-plugin-library/?id=72257, https://www.infosecmatter.com/nessus-plugin-library/?id=62785
Platforms Tested: Wordpress
2023
WordPress Plugin Duplicator < 1.5.7.1 - Unauthenticated Sensitive Data Exposure to Account Takeover
A severe vulnerability has been found in the directory */wordpress/wp-content/backups-dup-lite/tmp/*. This vulnerability exposes detailed information about the site, including its configuration, directories, files, and grants unauthorized access to sensitive data within the database, posing a risk of brute force attacks on password hashes and potential system compromise.
Mitigation:
To mitigate this vulnerability, restrict access to the /wp-content/backups-dup-lite/tmp/ directory and ensure proper access controls are in place. It is recommended to update the Duplicator plugin to version 1.5.7.1 or newer.