CVE-2013-4625

NUCLEI

Duplicator < 0.4.5 - Cross-Site Scripting via Package Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-4625. PoCs published by High-Tech Bridge. A Nuclei detection template is also available.

AI-analyzed exploit summary The exploit describes a reflected XSS vulnerability in the Duplicator WordPress plugin due to improper input sanitization in the installer.cleanup.php file. An attacker can inject arbitrary JavaScript via the 'package' parameter to steal cookies or perform other client-side attacks.

Description

Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by High-Tech Bridge · textwebappsphp
https://www.exploit-db.com/exploits/38676

The exploit describes a reflected XSS vulnerability in the Duplicator WordPress plugin due to improper input sanitization in the installer.cleanup.php file. An attacker can inject arbitrary JavaScript via the 'package' parameter to steal cookies or perform other client-side attacks.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Duplicator WordPress plugin 0.4.4
No auth needed
Prerequisites: Access to a vulnerable WordPress instance with the Duplicator plugin installed
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

WordPress Plugin Duplicator < 0.4.5 - Cross-Site Scripting
MEDIUMby daffainfo

References (7)

Core 7
Core References
Vendor Advisory x_refsource_misc
https://www.htbridge.com/advisory/HTB23162
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/61425
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/85939
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/95627
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-07/0161.html

Scores

EPSS 0.0779
EPSS Percentile 92.2%

Details

CWE
CWE-79
Status published
Products (3)
cory_lamle/duplicator 0.4.2
cory_lamle/duplicator 0.4.3
cory_lamle/duplicator < 0.4.4
Published Aug 09, 2013
Tracked Since Feb 18, 2026