Description
WordPress Plugin Backup, Restore and Migrate WordPress Sites With the XCloner is prone to a vulnerability which can be exploited by malicious people to disclose sensitive information. Input passed via the "config" parameter to wp-content/plugins/xcloner-backup-and-restore/cloner.cron.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources via directory traversal attacks. WordPress Plugin Backup, Restore and Migrate WordPress Sites With the XCloner version 3.0.3 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 3.0.4 or latest
References
Related Vulnerabilities
WordPress Plugin Countdown Block Security Bypass (1.1.1)
Oracle JRE CVE-2013-1486 Vulnerability (CVE-2013-1486)
OpenSSL Numeric Errors Vulnerability (CVE-2007-5135)
axios Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-45857)
WordPress Plugin Poll, Survey, Form & Quiz Maker by OpinionStage Cross-Site Scripting (19.6.24)