Lucene search

K
patchstackRicardo SanchezPATCHSTACK:FCA9BF36F77D52A9AA271324CD2DADD9
HistoryNov 20, 2017 - 12:00 a.m.

WordPress Duplicator plugin <=1.2.28 – Stored Cross-Site Scripting (XSS) vulnerability

2017-11-2000:00:00
Ricardo Sanchez
patchstack.com
5

EPSS

0.001

Percentile

33.5%

Stored Cross-Site Scripting (XSS) vulnerability found by Ricardo Sanchez in WordPress Duplicator plugin (versions <=1.2.28). The plugin is vulnerable due to incorrectly filtered values “url_new” and “logging”.

Solution

           Update the WordPress Duplicator plugin to the latest available version (at least version 1.2.30).

EPSS

0.001

Percentile

33.5%

Related for PATCHSTACK:FCA9BF36F77D52A9AA271324CD2DADD9