Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.152 - Cross-Site Request Forgery

2020-08-18 00:00
Chloe Chamberland

Strategic Overview

Status
Patched in 4.2.153
Affected Version< 4.2.153
CVSS9.8Critical
CVECVE-2020-35950
View all Backup, Restore and Migrate your sites with XCloner vulnerabilities

Vulnerability Overview

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).

Technical Analysis

REMEDIATION: Update to version 4.2.153, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C