CVE-2020-35948

Source
https://cve.org/CVERecord?id=CVE-2020-35948
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-35948.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-35948
Published
2021-01-01T04:15:13.497Z
Modified
2026-07-08T21:25:56.530761Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xclonerrestore.php writefile_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump.

References

Affected packages

Git / github.com/watchfulli/xcloner-wordpress

Affected ranges

Type
GIT
Repo
https://github.com/watchfulli/xcloner-wordpress
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:xcloner:xcloner:*:*:*:*:*:wordpress:*:*",
    "extracted_events": [
        {
            "introduced": "4.2.1"
        },
        {
            "fixed": "4.2.13"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

4.*
4.2.1
4.2.10
4.2.10a
4.2.10b
4.2.11
4.2.12
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
4.2.8r
4.2.9
4.2.9a
4.2.9b
4.2.9c
4.2.9d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-35948.json"