peter bassill · operator
$ cve CVE-2022-2552 JSON

CVE-2022-2552 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 11.3% (pctl 96)

Patch early

A public exploit exists.

Description

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS11.3% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploityes
Published2022-08-22
Last modified2026-06-17

Affected (1)

VendorProduct
awesomemotiveduplicator

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD