Description
WordPress Plugin Backup, Restore and Migrate WordPress Sites With the XCloner is prone to two vulnerabilities which can be exploited by malicious people to conduct cross-site scripting attacks. Successful exploitation of this vulnerability requires that "register_globals" is enabled. WordPress Plugin Backup, Restore and Migrate WordPress Sites With the XCloner version 3.0 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 3.0.1 or latest
References
Related Vulnerabilities
MySQL CVE-2018-2778 Vulnerability (CVE-2018-2778)
WordPress Plugin Kino Gallery TimThumb Arbitrary File Upload (1.0)
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-4412)
MySQL CVE-2018-2818 Vulnerability (CVE-2018-2818)
PostgreSQL Improper Certificate Validation Vulnerability (CVE-2012-0867)