CVE-2020-35950

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
01/01/2021
Last modified:
13/01/2021

Description

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xcloner:xcloner:*:*:*:*:*:wordpress:*:* 4.2.153 (excluding)