← Vulnerability feed

Vulnerability record · CVE-2023-6114 · published 26 December 2023

CVE-2023-6114: Awesomemotive duplicator vulnerability

Awesomemotive · Duplicator

The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.

7.5 CVSS 3.1 High EPSS 31% · top 1.8% CWE-552 · CWE-552
7.5CVSS 3.1 base score
31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-6114 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2020-11738WordPress Duplicator plugin directory traversal allows arbitrary file readThe Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) is vulnerable to directory traversal via ../ in the …KEVEPSS 98%analysed9.8CVE-2018-25095Awesomemotive duplicator vulnerabilityThe Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration fil…EPSS 0.92%9.8CVE-2018-17207WordPress Duplicator leftover installer files allow PHP code injection and RCESnap Creek Duplicator before 1.2.42 leaves installer.php and installer-backup.php accessible after installation. An attacker can reach those files an…EPSS 60%analysed7.5CVE-2022-2551Awesomemotive duplicator vulnerabilityThe Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of t…EPSS 17%6.1CVE-2023-33309Awesomemotive duplicator cross-site scripting vulnerabilityUnauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions.EPSS 0.38%6.1CVE-2018-7543Awesomemotive duplicator cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote atta…EPSS 3.3%5.3CVE-2022-2552Awesomemotive duplicator missing authentication for critical function vulnerabilityThe Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as serve…EPSS 11%7.5CVE-2025-11371Gladinet CentreStack and Triofox unauthenticated local file inclusionCentreStack and Triofox in default installation and configuration contain an unauthenticated local file inclusion flaw that allows unintended disclos…KEVEPSS 92%analysed

Source: NIST National Vulnerability Database (record CVE-2023-6114), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.