Unrated severityNVD Advisory· Published Aug 9, 2013· Updated Apr 29, 2026
CVE-2013-4625
CVE-2013-4625
Description
Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.
Affected products
4cpe:2.3:a:cory_lamle:duplicator:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cory_lamle:duplicator:*:*:*:*:*:*:*:*range: <=0.4.4
- cpe:2.3:a:cory_lamle:duplicator:0.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:cory_lamle:duplicator:0.4.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- archives.neohapsis.com/archives/bugtraq/2013-07/0161.htmlnvd
- osvdb.org/95627nvd
- packetstormsecurity.com/files/122535/WordPress-Duplicator-0.4.4-Cross-Site-Scripting.htmlnvd
- support.lifeinthegrid.com/knowledgebase.phpnvd
- www.securityfocus.com/bid/61425nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/85939nvd
- www.htbridge.com/advisory/HTB23162nvd
News mentions
0No linked articles in our index yet.