vendor:
Duplicator
by:
Dmitrii Ignatyev
6.1
CVSS
HIGH
Sensitive Data Exposure
200
CWE
Product Name: Duplicator
Affected Version From: 1.5.7.1
Affected Version To: 1.5.7.1
Patch Exists: YES
Related CWE: CVE-2023-6114
CPE: a:lifeinthegrid:duplicator:1.5.7.1
Platforms Tested: Wordpress
2023
Unauthenticated Sensitive Data Exposure in WordPress Plugin Duplicator < 1.5.7.1
A severe vulnerability has been found in the directory '/wordpress/wp-content/backups-dup-lite/tmp/' of WordPress Plugin Duplicator version 1.5.7.1. This vulnerability discloses significant information about the site's configuration, directories, files, and provides unauthorized access to sensitive database data, leading to potential brute force attacks on password hashes and system compromise.
Mitigation:
To mitigate this vulnerability, users should update to version 1.5.7.1 of the WordPress Plugin Duplicator. Additionally, restrict access to the '/wordpress/wp-content/backups-dup-lite/tmp/' directory.