Description
WordPress Plugin Backup, Restore and Migrate WordPress Sites With the XCloner is prone to a directory traversal vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information (filenames of previous backups) that could aid in further attacks. WordPress Plugin Backup, Restore and Migrate WordPress Sites With the XCloner version 3.1.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.1.5 or latest
References
https://gist.github.com/ldionmarcil/b223bb39694019d6f35a601ed7f841bf
https://wordpress.org/plugins/xcloner-backup-and-restore/changelog/
Related Vulnerabilities
WordPress Plugin CF7 Invisible reCAPTCHA Cross-Site Scripting (1.3.1)
WordPress Plugin Integration for WooCommerce and QuickBooks Cross-Site Scripting (1.1.8)
WordPress Plugin Uncanny Toolkit for LearnDash Cross-Site Request Forgery (3.6.3)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.7)
WordPress Plugin Analyticator Multiple Cross-Site Scripting Vulnerabilities (6.4.9.5)