Products: 1
    Vulnerabilities: 14
    Known Exploited: 0
    2
    Critical Level Threats
    2
    High Level Threats
    8
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-35948

    An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump.

    Last Modified: Nov 21, 2024
    Published: Jan 01, 2021

    CVE-2020-35950

    An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).

    Last Modified: Nov 21, 2024
    Published: Jan 01, 2021

    CVE-2020-13424

    The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.

    Last Modified: Nov 21, 2024
    Published: May 23, 2020

    CVE-2015-4336

    cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backup comments feature to create the file.

    Last Modified: Apr 12, 2025
    Published: Jun 17, 2015

    CVE-2015-4337

    Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the excl_manual parameter in the xcloner_show page to wpadmin/plugins.php.

    Last Modified: Apr 12, 2025
    Published: Jun 17, 2015
    Items Per Page