Black Friday Deals 40% OFF

Days
Hours
Minutes

Access violation vulnerability in Clone 2.4.5

The Clone plugin for WordPress is not secure and could potentially allow attackers to change data without permission. This is because the wpa_wpc_ajax_install_new() function does not have a check to make sure the user has the proper capabilities. This means that someone who is logged in and has at least subscriber-level access could install a backup plugin without authorization.

Detected in:

Clone fixed vulnerable versions: >= * <= 2.4.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.