Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesDuplicator

Duplicator vulnerabilities

Duplicator has 9 known vulnerabilities in this database. The most recent published record is dated 11 Jul 2024.

Known vulnerabilities
9
Active installs
1m+
Latest version
5.0.5
Last updated
29 Sep 2026
Most recent
11 Jul 2024
Duplicator vulnerabilities have been used in real attacks. CVE-2020-11738 (listed Nov 2021) is on the US CISA Known Exploited Vulnerabilities list. If your installed version is affected, update now and check the site for signs of compromise. Get help today or call 0208 088 8371.

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Sensitive data exposure
CVE-2024-6210
Medium 5.3Up to 1.5.9Fixed in a later version (latest 5.0.5)11 Jul 2024
Cross-site request forgery (CSRF)
CVE-2023-51681
Medium 6.5Up to 1.5.7Fixed in a later version (latest 5.0.5)28 Feb 2024
Security weakness
CVE-2018-25095
Critical 9.8Before 1.3.0Fixed in 1.3.08 Jan 2024
Security weakness
CVE-2023-6114
High 7.5Before 4.5.14.2Fixed in 4.5.14.226 Dec 2023
Security weakness
CVE-2022-2551
High 7.5Before 1.4.7Fixed in 1.4.722 Aug 2022
Authentication bypass
CVE-2022-2552
Medium 5.3Before 1.4.7.1Fixed in 1.4.7.122 Aug 2022
Path traversal
Exploited in the wild
CVE-2020-11738
High 7.5Before 3.8.7.1Fixed in 3.8.7.113 Apr 2020
Cross-site scripting (XSS)
CVE-2018-7543
Medium 6.1Not yet publishedCheck for an update26 Mar 2018
Cross-site scripting (XSS)
CVE-2013-4625
Not scoredUp to 0.4.4Fixed in a later version (latest 5.0.5)9 Aug 2013
Read the published descriptions
CVE-2024-6210, 11 Jul 2024
The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use. CVE record
CVE-2023-51681, 28 Feb 2024
Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator - WordPress Migration & Backup Plugin.This issue affects Duplicator - WordPress Migration & Backup Plugin: from n/a through 1.5.7. CVE record
CVE-2018-25095, 8 Jan 2024
The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server. CVE record
CVE-2023-6114, 26 Dec 2023
The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site. CVE record
CVE-2022-2551, 22 Aug 2022
The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating. CVE record
CVE-2022-2552, 22 Aug 2022
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site. CVE record
CVE-2020-11738, 13 Apr 2020
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init. CVE record
CVE-2018-7543, 26 Mar 2018
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter. CVE record
CVE-2013-4625, 9 Aug 2013
Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter. CVE record

What to do if you run Duplicator

If you run Duplicator, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Duplicator vulnerabilities

Free. We email you when a new vulnerability is published for Duplicator, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support