← Vulnerability feed

Vulnerability record · CVE-2022-2551 · published 22 August 2022

CVE-2022-2551: Awesomemotive duplicator vulnerability

Awesomemotive · Duplicator

The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating.

7.5 CVSS 3.1 High EPSS 17% · top 3.1% CWE-425 · CWE-425
7.5CVSS 3.1 base score
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-2551 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2020-11738WordPress Duplicator plugin directory traversal allows arbitrary file readThe Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) is vulnerable to directory traversal via ../ in the …KEVEPSS 98%analysed9.8CVE-2018-25095Awesomemotive duplicator vulnerabilityThe Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration fil…EPSS 0.92%9.8CVE-2018-17207WordPress Duplicator leftover installer files allow PHP code injection and RCESnap Creek Duplicator before 1.2.42 leaves installer.php and installer-backup.php accessible after installation. An attacker can reach those files an…EPSS 60%analysed7.5CVE-2023-6114Awesomemotive duplicator vulnerabilityThe Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` …EPSS 31%6.1CVE-2023-33309Awesomemotive duplicator cross-site scripting vulnerabilityUnauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions.EPSS 0.38%6.1CVE-2018-7543Awesomemotive duplicator cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote atta…EPSS 3.3%5.3CVE-2022-2552Awesomemotive duplicator missing authentication for critical function vulnerabilityThe Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as serve…EPSS 11%7.5CVE-2024-45195Apache OFBiz forced browsing exposes restricted endpointsApache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functio…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2022-2551), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.