Description
WordPress Plugin Duplicator-WordPress Migration is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create and download backup files. WordPress Plugin Duplicator-WordPress Migration version 0.5.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.5.10 or latest
References
http://security.szurek.pl/duplicator-058-privilege-escalation.html
https://www.exploit-db.com/exploits/36112/
http://packetstormsecurity.com/files/130439/WordPress-Duplicator-0.5.8-Privilege-Escalation.html
Related Vulnerabilities
WordPress Plugin The Plus Addons for Elementor Open Redirect (4.1.9)
WordPress Plugin WP-PostRatings Cross-Site Scripting (1.50)
MySQL CVE-2023-21880 Vulnerability (CVE-2023-21880)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-1580)
WordPress Plugin Async JavaScript Security Bypass (2.19.07.14)