CVE-2020-35948
53Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.9epss 25%
from disclosure to weapon181 days
Published on NVDJan 1
1st PoC+181d
exploitation probability
25%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/50077unverifiedcve_referencepacketstormsecurity.com/files/163336/WordPress-XCloner-4.2.12-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/163336/WordPress-XCloner-4.2.12-Remote-Code-Execution.htmlhttps://github.com/Hacker5preme/Exploits/tree/main/Wordpress/CVE-2020-35948https://wpscan.com/vulnerability/10412https://www.wordfence.com/blog/2020/09/critical-vulnerabilities-patched-in-xcloner-backup-and-restore-plugin/