Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.16 - Unauthenticated Plugin Settings Reset
2022-06-06 00:00
Krzysztof ZającStrategic Overview
StatusPatched in 4.3.6
Affected PluginBackup, Restore and Migrate your sites with XCloner
Affected Version
<= 4.2.16CVSS9.8Critical
CVE
CVE-2022-0444Vulnerability Overview
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.
Technical Analysis
REMEDIATION: Update to version 4.3.6, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C