HIGH

CVE-2020-35948

CVSS v3

8.8

HIGH

EPSS Score

36.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump.

Technical details

Published
1/1/2021

Frequently asked questions

What is CVE-2020-35948?

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump.

Is CVE-2020-35948 actively exploited?

Active exploitation of CVE-2020-35948 has not been confirmed. The EPSS score is 36.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-35948?

CVE-2020-35948 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2020-35948 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.