HomeWordPress vulnerabilitiesDuplicator
Duplicator vulnerabilities
Duplicator has 9 known vulnerabilities in this database. The most recent published record is dated 11 Jul 2024.
- Known vulnerabilities
- 9
- Active installs
- 1m+
- Latest version
- 5.0.5
- Last updated
- 29 Sep 2026
- Most recent
- 11 Jul 2024
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Sensitive data exposure CVE-2024-6210 | Medium 5.3 | Up to 1.5.9 | Fixed in a later version (latest 5.0.5) | 11 Jul 2024 |
| Cross-site request forgery (CSRF) CVE-2023-51681 | Medium 6.5 | Up to 1.5.7 | Fixed in a later version (latest 5.0.5) | 28 Feb 2024 |
| Security weakness CVE-2018-25095 | Critical 9.8 | Before 1.3.0 | Fixed in 1.3.0 | 8 Jan 2024 |
| Security weakness CVE-2023-6114 | High 7.5 | Before 4.5.14.2 | Fixed in 4.5.14.2 | 26 Dec 2023 |
| Security weakness CVE-2022-2551 | High 7.5 | Before 1.4.7 | Fixed in 1.4.7 | 22 Aug 2022 |
| Authentication bypass CVE-2022-2552 | Medium 5.3 | Before 1.4.7.1 | Fixed in 1.4.7.1 | 22 Aug 2022 |
| Path traversal Exploited in the wild CVE-2020-11738 | High 7.5 | Before 3.8.7.1 | Fixed in 3.8.7.1 | 13 Apr 2020 |
| Cross-site scripting (XSS) CVE-2018-7543 | Medium 6.1 | Not yet published | Check for an update | 26 Mar 2018 |
| Cross-site scripting (XSS) CVE-2013-4625 | Not scored | Up to 0.4.4 | Fixed in a later version (latest 5.0.5) | 9 Aug 2013 |
Read the published descriptions
- CVE-2024-6210, 11 Jul 2024
- The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use. CVE record
- CVE-2023-51681, 28 Feb 2024
- Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator - WordPress Migration & Backup Plugin.This issue affects Duplicator - WordPress Migration & Backup Plugin: from n/a through 1.5.7. CVE record
- CVE-2018-25095, 8 Jan 2024
- The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server. CVE record
- CVE-2023-6114, 26 Dec 2023
- The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site. CVE record
- CVE-2022-2551, 22 Aug 2022
- The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating. CVE record
- CVE-2022-2552, 22 Aug 2022
- The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site. CVE record
- CVE-2020-11738, 13 Apr 2020
- The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init. CVE record
- CVE-2018-7543, 26 Mar 2018
- Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter. CVE record
- CVE-2013-4625, 9 Aug 2013
- Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter. CVE record
What to do if you run Duplicator
If you run Duplicator, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Duplicator vulnerabilities
Free. We email you when a new vulnerability is published for Duplicator, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.