WordPress Plugin Vulnerabilities

Duplicator < 0.5.16 - SQL Injection & CSRF

Description

An authorised user with "export" permission or a remote unauthenticated attacker could use this vulnerability to execute arbitrary SQL queries on the victim WordPress web site by enticing an authenticated admin (CSRF).

Proof of Concept

Affects Plugins

Fixed in 0.5.16

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Submitter
Claudio Viviani
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2015-04-10 (about 11 years ago)
Added
2015-04-10 (about 11 years ago)
Last Updated
2019-10-21 (about 6 years ago)

Other