MEDIUM
CVE-2026-48965
CVSS
6.5
Description
Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.
Summary dbcve.org
XCloner WordPress backup plugin versions 4.8.6 and prior contain a vulnerability allowing unauthorized access to subscriber-sensitive data. The exposure likely involves improper access controls on backup files or sensitive information stored within the plugin's data structures, potentially exposing user credentials, personal information, or backup content to unauthorized subscribers.
Mitigation
Update XCloner plugin to a version beyond 4.8.6. If no patch is available, consider disabling the plugin until a fix is released, or implement additional access controls at the web server level to restrict sensitive plugin directories.
Weakness (CWE)
CWE-201
EPSS Score
0.33%
Probability of exploitation in next 30 days
25.9th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.