CVE-2014-9262

HIGH

Wordpress <0.5.10 - Authenticated RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-9262. PoCs published by Kacper Szurek.

AI-analyzed exploit summary This exploit demonstrates a privilege escalation vulnerability in Duplicator 0.5.8, allowing any registered user to create and download backup files via unauthorized AJAX actions. The PoC outlines steps to trigger backup creation and retrieval, bypassing intended access controls.

Description

The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.

Exploits (1)

exploitdb WORKING POC
by Kacper Szurek · textwebappsphp
https://www.exploit-db.com/exploits/36112

This exploit demonstrates a privilege escalation vulnerability in Duplicator 0.5.8, allowing any registered user to create and download backup files via unauthorized AJAX actions. The PoC outlines steps to trigger backup creation and retrieval, bypassing intended access controls.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Duplicator WordPress Plugin 0.5.8
Auth required
Prerequisites: Registered user account on the WordPress site
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/36112/

Scores

CVSS v3 8.2
EPSS 0.0749
EPSS Percentile 93.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Details

CWE
CWE-264
Status published
Products (1)
snapcreek/duplicator < 0.5.8
Published Aug 07, 2017
Tracked Since Feb 18, 2026