CVE-2020-35948
Summary
| CVE | CVE-2020-35948 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-01 04:15:00 UTC |
| Updated | 2022-02-22 10:14:00 UTC |
| Description | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| XCloner Backup and Restore 4.2.1 - 4.2.12 - Unprotected AJAX Action Security Vulnerability | MISC | wpscan.com | Exploit, Third Party Advisory |
| Exploits/Wordpress/CVE-2020-35948 at main · Hacker5preme/Exploits · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| WordPress XCloner 4.2.12 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Critical Vulnerabilities Patched in XCloner Backup and Restore Plugin | MISC | www.wordfence.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.