PoC Index

CVE-2018-25095

CRITICAL 9.8EPSS 0.9%

The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.92% chance of exploitation in the next 30 days, 58th percentile
Published
2024-01-08
Updated
2025-06-03

Proof-of-concept exploits (1)

References

Related