What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issue affects Duplicator – WordPress Migration & Backup Plugin: from n/a through 1.5.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issue affects Duplicator – WordPress Migration & Backup Plugin: from n/a through 1.5.7.
Explanation of Vulnerability in Simple Terms
Duplicator versions up to 1.5.7 contain a cross-site request forgery vulnerability that allows an attacker to perform unauthorized actions on behalf of a site administrator. The attacker must trick an admin into visiting a malicious webpage while logged into WordPress. This can result in site disruption or data loss through unwanted backup or migration operations.
What an attacker can do
Perform backup, migration, or other plugin actions on the site without the admin's knowledge.
Potential impact on your site
An attacker can trigger unintended backups, migrations, or deletions that disrupt your site or expose data.
Conditions required to exploit
Site admin must be logged into WordPress and visit an attacker-controlled webpage.
Key dates
External resources
Related vulnerabilities