Record summary

CVE-2022-2552 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Duplicator

Default status: unaffected

CVE ListBefore 1.4.7affected

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Duplicator 1.4.7 - Information DisclosureExploitDB exploitby SecuriTrustNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMDuplicator < 1.4.7.1 - Information DisclosureCVSS 5.3

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.

Impact

Unauthenticated attackers can access sensitive system information including server software versions, PHP version, and full filesystem paths through the exposed installer endpoint, providing valuable reconnaissance data for targeted attacks.

Remediation

Update Duplicator plugin to version 1.4.7.1 or later that requires authentication before displaying system information.

WeaknessesCWE-862
Authorsiamnoooob, ritikchaddha
Template tagscvecve2022wpwp-pluginwordpressduplicatordisclosurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:snapcreek:duplicator:*:*:*:*:lite:wordpress:*:*
FOFA: body="/wp-content/plugins/duplicator"

Source: ProjectDiscovery

References

3