← Vulnerability feed

Vulnerability record · CVE-2018-7543 · published 26 March 2018

CVE-2018-7543: Awesomemotive duplicator cross-site scripting vulnerability

Awesomemotive · Duplicator

Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.

6.1 CVSS 3.1 Medium EPSS 3.3% · top 11.8% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
3.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-7543 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2020-11738WordPress Duplicator plugin directory traversal allows arbitrary file readThe Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) is vulnerable to directory traversal via ../ in the …KEVEPSS 98%analysed9.8CVE-2018-25095Awesomemotive duplicator vulnerabilityThe Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration fil…EPSS 0.92%9.8CVE-2018-17207WordPress Duplicator leftover installer files allow PHP code injection and RCESnap Creek Duplicator before 1.2.42 leaves installer.php and installer-backup.php accessible after installation. An attacker can reach those files an…EPSS 60%analysed7.5CVE-2023-6114Awesomemotive duplicator vulnerabilityThe Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` …EPSS 31%7.5CVE-2022-2551Awesomemotive duplicator vulnerabilityThe Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of t…EPSS 17%6.1CVE-2023-33309Awesomemotive duplicator cross-site scripting vulnerabilityUnauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions.EPSS 0.38%5.3CVE-2022-2552Awesomemotive duplicator missing authentication for critical function vulnerabilityThe Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as serve…EPSS 11%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed

Source: NIST National Vulnerability Database (record CVE-2018-7543), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.