← Vulnerability feed

Vulnerability record · CVE-2018-25095 · published 8 January 2024

CVE-2018-25095: Awesomemotive duplicator vulnerability

Awesomemotive · Duplicator

The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.

9.8 CVSS 3.1 Critical EPSS 0.92% · top 41.2%
9.8CVSS 3.1 base score
0.92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-25095 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2020-11738WordPress Duplicator plugin directory traversal allows arbitrary file readThe Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) is vulnerable to directory traversal via ../ in the …KEVEPSS 98%analysed9.8CVE-2018-17207WordPress Duplicator leftover installer files allow PHP code injection and RCESnap Creek Duplicator before 1.2.42 leaves installer.php and installer-backup.php accessible after installation. An attacker can reach those files an…EPSS 60%analysed7.5CVE-2023-6114Awesomemotive duplicator vulnerabilityThe Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` …EPSS 31%7.5CVE-2022-2551Awesomemotive duplicator vulnerabilityThe Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of t…EPSS 17%6.1CVE-2023-33309Awesomemotive duplicator cross-site scripting vulnerabilityUnauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions.EPSS 0.38%6.1CVE-2018-7543Awesomemotive duplicator cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote atta…EPSS 3.3%5.3CVE-2022-2552Awesomemotive duplicator missing authentication for critical function vulnerabilityThe Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as serve…EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2018-25095), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.