MEDIUM

CVE-2026-48965

2026-06-15 CVSS v3.1
CVSS
6.5

Description

Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.

Summary dbcve.org

XCloner WordPress backup plugin versions 4.8.6 and prior contain a vulnerability allowing unauthorized access to subscriber-sensitive data. The exposure likely involves improper access controls on backup files or sensitive information stored within the plugin's data structures, potentially exposing user credentials, personal information, or backup content to unauthorized subscribers.

Mitigation

Update XCloner plugin to a version beyond 4.8.6. If no patch is available, consider disabling the plugin until a fix is released, or implement additional access controls at the web server level to restrict sensitive plugin directories.

Weakness (CWE)

CWE-201

EPSS Score

0.33%
Probability of exploitation in next 30 days
25.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE