← All CVEs

CVE-2020-35948

critical · 9.9

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump.

9.9
CVSS
24.9%
EPSS (exploit prob.)
98th
EPSS percentile
2021-01-01
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-863

Affected products

VendorProductAffected versions
xclonerxcloner>= 4.2.1, < 4.2.13

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-35948