CVE-2018-25095: Duplicator < 1.3.0 - Unauthenticated RCE
Published Jan 8, 2024
·Updated
The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.
Affected Software
1 affected component
Awesomemotive Duplicator Wordpress<1.3.0
Event History
Jan 8, 2024
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-25095?
CVE-2018-25095 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2018-25095?
To fix CVE-2018-25095, update the Duplicator plugin to version 1.3.0 or higher.
3
What software is affected by CVE-2018-25095?
CVE-2018-25095 affects the Duplicator plugin for WordPress versions prior to 1.3.0.
4
What could happen if I don’t address CVE-2018-25095?
If left unaddressed, CVE-2018-25095 could allow attackers to run arbitrary code on your server.
5
Is it safe to leave the installer script after using CVE-2018-25095?
No, it is unsafe to leave the installer script on your site after use, as it can be exploited.