CVE-2022-2552

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
22/08/2022
Last modified:
02/02/2026

Description

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:awesomemotive:duplicator:*:*:*:*:lite:wordpress:*:* 1.4.7.1 (excluding)