Snapcreek
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Snapcreek product.
RSS Feeds for Snapcreek security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Snapcreek products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Snapcreek Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 0 vulnerabilities in Snapcreek. Snapcreek did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 1 | 9.80 |
| 2023 | 1 | 4.80 |
| 2022 | 2 | 6.40 |
| 2021 | 0 | 0.00 |
| 2020 | 1 | 0.00 |
| 2019 | 0 | 0.00 |
| 2018 | 2 | 9.80 |
It may take a day or so for new Snapcreek vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Snapcreek Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2018-25095 | Jan 08, 2024 |
Duplicator WP Plugin 1.3.0 Installer Script Code InjectionThe Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server. |
|
| CVE-2023-24398 | Apr 07, 2023 |
Snap Creek EZP Coming Soon Page <=1.0.7.3 XSS FlawAuth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Coming Soon Page plugin <= 1.0.7.3 versions. |
|
| CVE-2022-2552 | Aug 22, 2022 |
Duplicator WP Plugin <1.4.7 Unauthenticated Info DisclosureThe Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site. |
|
| CVE-2022-2551 | Aug 22, 2022 |
Wordpress Duplicator<=1.4.6 Backup URL Disclosure via Installer EndpointThe Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating. |
|
| CVE-2020-11738 | Apr 13, 2020 |
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal viaThe Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init. |
|
| CVE-2018-17207 | Sep 19, 2018 |
An issue was discovered in Snap Creek Duplicator before 1.2.42An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution. |
|
| CVE-2018-7543 | Mar 26, 2018 |
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPressCross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter. |
|