vendor:
WordPress Plugin Duplicator
by:
Dmitrii Ignatyev
6.1
CVSS
HIGH
Sensitive Data Exposure
200
CWE
Product Name: WordPress Plugin Duplicator
Affected Version From: 1.5.7.1
Affected Version To: 1.5.7.1
Patch Exists: YES
Related CWE: CVE-2023-6114
CPE: a:wordpress:duplicator:1.5.7.1
Platforms Tested: Wordpress
2023
WordPress Plugin Duplicator < 1.5.7.1 - Unauthenticated Sensitive Data Exposure to Account Takeover
A severe vulnerability was found in WordPress Plugin Duplicator version 1.5.7.1. The flaw allows unauthorized access to sensitive data in the database and other information on the site, leading to potential brute force attacks on password hashes and complete system compromise. Exploiting this flaw poses a significant security risk.
Mitigation:
Update to version 1.5.7.1 or later to patch this vulnerability. Avoid storing sensitive information in the exposed directory.