Description
WordPress Plugin Backup, Restore and Migrate WordPress Sites With the XCloner is prone to arbitrary command execution, directory traversal and information disclosure vulnerabilities. An attacker may leverage these issues to execute arbitrary commands within the context of the vulnerable application or to obtain potentially sensitive information which could help in launching further attacks. WordPress Plugin Backup, Restore and Migrate WordPress Sites With the XCloner version 3.1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.1.2 or latest
References
http://www.vapid.dhs.org/advisories/wordpress/plugins/Xcloner-v3.1.1/
http://seclists.org/oss-sec/2014/q4/538
http://security.szurek.pl/xcloner-backup-and-restore-311-backup-download.html
Related Vulnerabilities
WordPress Plugin Contact Form 7 Database Addon-CFDB7 Unspecified Vulnerability (1.2.5.3)
WordPress Plugin Launcher:Coming Soon & Maintenance Mode Cross-Site Scripting (1.0.10)
WordPress Plugin Activity Log Cross-Site Scripting (2.3.1)
WordPress Plugin StatPress Cross-Site Scripting (1.2.9.1)
WordPress Plugin User Access Manager Cross-Site Scripting (1.2.14)