Lucene search

K
patchstackLarry W. CashdollarPATCHSTACK:5A9B3CD44119C4DD5669E6C658AC44F5
HistoryNov 04, 2014 - 12:00 a.m.

WordPress XCloner Plugin <= 3.1.1 - Multiple Vulnerabilities

2014-11-0400:00:00
Larry W. Cashdollar
patchstack.com
4

0.0004 Low

EPSS

Percentile

5.1%

There are multiple vulnerabilities in this plugin, such as arbitrary command execution, clear text MySQL password exposure through html text box under configuration panel, MySQL password exposed to process table, database backups exposed to local users due to open file permissions, authenticated remote file access and unauthenticated remote access to backup files via easily guessable file names.

Solution

           Update the plugin. 
CPENameOperatorVersion
xclonerle3.1.1

0.0004 Low

EPSS

Percentile

5.1%

Related for PATCHSTACK:5A9B3CD44119C4DD5669E6C658AC44F5