The Duplicator WordPress plugin before 1.5.7.1,...
High severity
Unreviewed
Published
Dec 26, 2023
to the GitHub Advisory Database
•
Updated Jan 5, 2024
Description
Published by the National Vulnerability Database
Dec 26, 2023
Published to the GitHub Advisory Database
Dec 26, 2023
Last updated
Jan 5, 2024
The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the
backups-dup-lite/tmp
directory (or thebackups-dup-pro/tmp
directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.References