S4E just found a critical-severity finding from ruijie rg-uac remote code execution scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2013-4625 Scanner

CVE-2013-4625 scanner - Cross-Site Scripting (XSS) vulnerability in Duplicator plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2013-4625
4.3
CVSS

Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The Duplicator plugin for WordPress is an essential tool for website owners and developers. It serves as a backup, migration, and cloning tool that enables users to easily move their content from one website to another. It does this by creating a compressed package of the website's files and database, which can be easily migrated or copied to a different location. The plugin is especially useful for website developers who frequently move content between staging and production environments.

However, in CVE-2013-4625, a cross-site scripting (XSS) vulnerability was detected in files/installer.cleanup.php of the Duplicator plugin before version 0.4.5. This vulnerability allowed remote attackers to inject arbitrary web script or HTML via the package parameter. The attack could be carried out by an attacker tricking a user into clicking a malicious link or by exploiting other vulnerabilities in the website.

When this vulnerability is exploited, it can lead to the attacker gaining unauthorized access to a website's database, files, and confidential information. This puts the website at risk of data theft, defacement, and other malicious attacks. The attacker can also use the vulnerability to inject malware into the website, turning it into a platform for launching further attacks on other websites.

To further safeguard digital assets, s4e.io provides comprehensive security solutions that help website owners and developers to detect and fix vulnerabilities in real-time. By leveraging pro features such as malware scanning, vulnerability assessment, and web application firewall, users can quickly identify and fix vulnerabilities, thereby reducing the risk of attacks and data breaches. With s4e.io, website owners can confidently secure their digital assets and focus on growing their business.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended that users of the Duplicator plugin update to version 0.4.5 or later immediately. Other precautions that can be taken include: 

  • Using a reliable security plugin for WordPress that can scan and detect vulnerabilities in plugins and themes.
  • Ensuring that all plugins and themes are updated to their latest versions.
  • Regularly backing up website files and database to an offsite location.
  • Restricting users' permissions to their required level, thereby reducing the surface area for attack.
  • Training users to recognize and avoid suspicious links and attachments.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2013-4625 scanner - Cross-Site Scripting (XSS) vulnerability in Duplicator plugin for WordPress | S4E