XCloner
cpe:2.3:a:xcloner:xcloner:*:*:*:*:*:*:*, +1 more
- <= 4.8.2
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the XCloner Backup and Restore WordPress plugin, affecting all versions through 4.8.2. The issue arises from inadequate nonce validation in the Xcloner_Remote_Storage:save() function, allowing unauthenticated attackers to manipulate FTP backup configurations. Exploitation requires tricking a site administrator into clicking a link, which could lead to the exfiltration of sensitive site data by redirecting backups to an attacker-controlled FTP site.
Exploitation of this vulnerability could result in unauthorized modification of FTP backup settings, allowing attackers to redirect backups to a location of their choice and potentially access sensitive site information.
Users are advised to update the XCloner Backup and Restore plugin to version 4.8.3 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.