CVE-2020-35948
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin 4.2.1 - 4.2.12 - Unprotected AJAX Actions
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump.
Se detectó un problema en el plugin XCloner Backup and Restore versiones anteriores a 4.2.13 para WordPress. Otorgaba a atacantes autenticados la capacidad de modificar archivos arbitrarios, incluyendo archivos PHP. Hacerlo permitiría a un atacante lograr una ejecución de código remota. La función write_file_action del archivo xcloner_restore.php podría sobrescribir wp-config.php, por ejemplo. Alternativamente, un atacante podría crear una cadena de explotaciones para obtener un volcado de base de datos.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-08-18 CVE Published
- 2021-01-01 CVE Reserved
- 2021-07-01 First Exploit
- 2024-08-04 CVE Updated
- 2024-09-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
- CWE-863: Incorrect Authorization
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/163336/WordPress-XCloner-4.2.12-Remote-Code-Execution.html | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xcloner Search vendor "Xcloner" | Xcloner Search vendor "Xcloner" for product "Xcloner" | >= 4.2.1 < 4.2.13 Search vendor "Xcloner" for product "Xcloner" and version " >= 4.2.1 < 4.2.13" | wordpress |
Affected
|