CVE-2022-2552
Duplicator < 1.4.7.1 - Unauthenticated System Information Disclosure
Record summary
CVE-2022-2552 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DuplicatorDefault status: unaffected | CVE List | Before 1.4.7 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Duplicator 1.4.7 - Information DisclosureExploitDB exploitby SecuriTrustNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMDuplicator < 1.4.7.1 - Information DisclosureCVSS 5.3
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
Impact
Unauthenticated attackers can access sensitive system information including server software versions, PHP version, and full filesystem paths through the exposed installer endpoint, providing valuable reconnaissance data for targeted attacks.
Remediation
Update Duplicator plugin to version 1.4.7.1 or later that requires authentication before displaying system information.
Source: ProjectDiscovery