CVE-2022-2552
MEDIUM 5.3EPSS 11.3%
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
- CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - EPSS
- 11.30% chance of exploitation in the next 30 days, 96th percentile
- Nuclei
- medium · CWE-862
- Published
- 2022-08-22
- Updated
- 2024-08-03
Proof-of-concept exploits (2)
- SecuriTrust/CVEsLab/tree/main/CVE-2022-2552
- https://wpscan.com/vulnerability/6b540712-fda5-4be6-ae4b-bd30a9d9d698