Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.16 - Unauthenticated Plugin Settings Reset

2022-06-06 00:00
Krzysztof Zając

Strategic Overview

Status
Patched in 4.3.6
Affected Version<= 4.2.16
CVSS9.8Critical
CVECVE-2022-0444
View all Backup, Restore and Migrate your sites with XCloner vulnerabilities

Vulnerability Overview

The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.

Technical Analysis

REMEDIATION: Update to version 4.3.6, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C