CVE-2022-2551
Summary
| CVE | CVE-2022-2551 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-22 15:15:00 UTC |
| Updated | 2022-08-23 18:56:00 UTC |
| Description | The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating. |
Risk And Classification
Problem Types: CWE-425
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Snapcreek | Duplicator | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Duplicator < 1.4.7 - Unauthenticated Backup Download WordPress Security Vulnerability | MISC | wpscan.com | |
| CVEsLab/CVE-2022-2551 at main · SecuriTrust/CVEsLab · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Ihsan Sencan
There are currently no legacy QID mappings associated with this CVE.