Xcloner is a WordPress backup and migration plugin that, despite its narrow product footprint, occupies a high-value niche in site administration and recovery workflows. Its vulnerabilities concentrate in application-layer security boundaries typical of web-facing backup tools: cross-site request forgery, path traversal, code injection, improper input validation, and exposure of sensitive configuration data frequently acquire public exploit tooling. Defenders should treat this plugin's releases as requiring prompt attention due to its privileged role in site backup and restoration; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xcloner over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35948HIGH An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP f | Jan 1, 2021 | 8.8 | 53 | NO | YES |
CVE-2014-8603MEDIUM cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file | Jun 10, 2015 | 6.5 | 34 | NO | YES |
CVE-2014-2340MEDIUM Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests | Apr 3, 2014 | 6.8 | 33 | NO | YES |
CVE-2014-2996HIGH XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters | Apr 25, 2014 | 7.1 | 31 | NO | YES |
CVE-2014-2579HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication of administrators for requests | Apr 25, 2014 | 7.6 | 31 | NO | YES |
CVE-2020-35950HIGH An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint). | Jan 1, 2021 | 8.8 | 26 | NO | NO |
CVE-2014-8605MEDIUM The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows r | Jun 10, 2015 | 5.0 | 25 | NO | YES |
CVE-2014-8604MEDIUM The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obta | Jun 10, 2015 | 5.0 | 25 | NO | YES |
CVE-2014-8606MEDIUM Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the fil | Jun 10, 2015 | 4.0 | 22 | NO | YES |
CVE-2015-4336MEDIUM cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharac | Jun 17, 2015 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xcloner.
Media articles that mention a CVE ID that affects a product developed by Xcloner — matched by CVE ID, not by vendor name.