Vulnerability Bulletins

Active Attack on Recently Patched Duplicator Plugin Vulnerability Affects Over 1 Million Sites


System information

   
Affected software Wordpress

Description

https://www.wordfence.com/blog/2020/02/active-attack-on-recently-patched-duplicator-plugin-vulnerability-affects-over-1-million-sites/ Description: Unauthenticated Arbitrary File DownloadAffected Plugin: DuplicatorAffected Versions: <= 1.3.26CVSS Score: 7.5 (High)CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NPatched Version: 1.3.28 A critical security update was recently issued for Duplicator, one of the most popular plugins in the WordPress ecosystem. Over a million WordPress

More info:

https://www.wordfence.com/blog/2020/02/active-attack-on-recently-patched-duplicator-plugin-vulnerability-affects-over-1-million-sites/

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2020-02-21
Ministerio de Defensa
CNI
CCN
CCN-CERT