Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2024-11-21

CVE-2024-6559 - Restore And Migrate Wordpress Sites With The Xcloner Plugin

The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.7.3. This is due the plugin utilizing sabre without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

PLUGIN Restore And Migrate Wordpress Sites With The Xcloner

CVE-2024-6559

MEDIUM CVSS 5.3 2024-07-16
Threat Entry Updated 2024-11-21

CVE-2022-0444 - Restore And Migrate Wordpress Sites With The Xcloner Plugin

The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.

PLUGIN Restore And Migrate Wordpress Sites With The Xcloner

CVE-2022-0444

MEDIUM CVSS 4.3 2022-06-27
Scroll to top