Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xcloner

First CVE: Apr 3, 2014Active for: 12 yearsTotal CVEs: 14
45.2
VTI Score
High

Xcloner is a WordPress backup and migration plugin that, despite its narrow product footprint, occupies a high-value niche in site administration and recovery workflows. Its vulnerabilities concentrate in application-layer security boundaries typical of web-facing backup tools: cross-site request forgery, path traversal, code injection, improper input validation, and exposure of sensitive configuration data frequently acquire public exploit tooling. Defenders should treat this plugin's releases as requiring prompt attention due to its privileged role in site backup and restoration; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
3.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Xcloner over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2014
12 years ago
Most Recent CVE
Jan 1, 2021
2,030 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-35948HIGH
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP f
Jan 1, 20218.853NOYES
CVE-2014-8603MEDIUM
cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file
Jun 10, 20156.534NOYES
CVE-2014-2340MEDIUM
Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests
Apr 3, 20146.833NOYES
CVE-2014-2996HIGH
XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters
Apr 25, 20147.131NOYES
CVE-2014-2579HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication of administrators for requests
Apr 25, 20147.631NOYES
CVE-2020-35950HIGH
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).
Jan 1, 20218.826NONO
CVE-2014-8605MEDIUM
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows r
Jun 10, 20155.025NOYES
CVE-2014-8604MEDIUM
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obta
Jun 10, 20155.025NOYES
CVE-2014-8606MEDIUM
Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the fil
Jun 10, 20154.022NOYES
CVE-2015-4336MEDIUM
cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharac
Jun 17, 20156.520NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
14%
57%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (21.4%)
Unknown11 (78.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (21.4%)
High0 (0.0%)
Unknown11 (78.6%)
User Interaction
None2 (14.3%)
Unknown11 (78.6%)
Required1 (7.1%)
Privileges Required
Low2 (14.3%)
High0 (0.0%)
None1 (7.1%)
Unknown11 (78.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
64.3% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xcloner.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xcloner — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xcloner's Products

View all 1 CNAs →

Top CWEs