Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-9262. PoCs published by Kacper Szurek.
AI-analyzed exploit summary This exploit demonstrates a privilege escalation vulnerability in Duplicator 0.5.8, allowing any registered user to create and download backup files via unauthorized AJAX actions. The PoC outlines steps to trigger backup creation and retrieval, bypassing intended access controls.
Description
The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
Exploits (1)
This exploit demonstrates a privilege escalation vulnerability in Duplicator 0.5.8, allowing any registered user to create and download backup files via unauthorized AJAX actions. The PoC outlines steps to trigger backup creation and retrieval, bypassing intended access controls.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N