Description
WordPress Plugin Backup, Restore and Migrate WordPress Sites With the XCloner is prone to arbitrary command execution, directory traversal and information disclosure vulnerabilities. An attacker may leverage these issues to execute arbitrary commands within the context of the vulnerable application or to obtain potentially sensitive information which could help in launching further attacks. WordPress Plugin Backup, Restore and Migrate WordPress Sites With the XCloner version 3.1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.1.2 or latest
References
http://www.vapid.dhs.org/advisories/wordpress/plugins/Xcloner-v3.1.1/
http://seclists.org/oss-sec/2014/q4/538
http://security.szurek.pl/xcloner-backup-and-restore-311-backup-download.html
Related Vulnerabilities
WordPress Plugin dsIDXpress IDX Cross-Site Scripting (2.1.0)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-6455)
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-4225)
WordPress Plugin BuddyPress Arbitrary File Deletion (2.7.3)
WordPress 4.8.x Arbitrary File Deletion Vulnerability (4.8 - 4.8.6)