nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6210 CVE-2024-6210
MEDIUM
Duplicator <= 1.5.9 - Full Path Disclosure
Record summary
CVE-2024-6210 has a selected CVSS score of 5.3 (medium).
Description
The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 24, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & MoreBrowse smub / Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & MoreDefault status: unaffected | CVE List | Through 1.5.9 | affected |
duplicatorBrowse snapcreek / duplicatorDefault status: unknown | CVE List | Through 1.5.9 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/duplicator/trunk/installer/dup-installer/main.installer.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3108563/duplicator/trunk/installer/dup-installer/main.installer.php?old=3073248&old_path=duplicator%2Ftrunk%2Finstaller%2Fdup-installer%2Fmain.installer.php wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/d47d582d-7c90-4f49-aee1-03a8775b850d?source=cve