Description
WordPress Plugin Backup, Restore and Migrate WordPress Sites With the XCloner is prone to arbitrary command execution, directory traversal and information disclosure vulnerabilities. An attacker may leverage these issues to execute arbitrary commands within the context of the vulnerable application or to obtain potentially sensitive information which could help in launching further attacks. WordPress Plugin Backup, Restore and Migrate WordPress Sites With the XCloner version 3.1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.1.2 or latest
References
http://www.vapid.dhs.org/advisories/wordpress/plugins/Xcloner-v3.1.1/
http://seclists.org/oss-sec/2014/q4/538
http://security.szurek.pl/xcloner-backup-and-restore-311-backup-download.html
Related Vulnerabilities
Atlassian Confluence Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-6342)
Mailman Other Vulnerability (CVE-2002-0389)
Apache Tomcat Other Vulnerability (CVE-2010-3718)
WordPress Plugin Wordfence Security-Firewall & Malware Scan Cross-Site Scripting (5.1.4)
WordPress Plugin Booking.com Product Helper Unspecified Vulnerability (1.0.3)