Sale of a 0-Day Vulnerability Chain for the WordPress Duplicator Plugin
Dark Web2026-08-31, 11:03
For informational purposes only.
Affected product: Duplicator – Backups & Migration Plugin
Vulnerability types: unauthenticated site takeover / backup disclosure / information disclosure
Price: $1,850
The seller claims to be offering a chain of three vulnerabilities affecting Duplicator, a popular WordPress plugin used for website backups and migrations. According to the post, the most serious issue allows an unauthenticated attacker to fully take over a site if certain Duplicator migration artifacts were left behind on the server after a migration.
In the first scenario, the attacker can allegedly abuse Duplicator’s leftover installation mechanisms to gain administrative access to WordPress. The seller claims this can then be used to exfiltrate the database, install plugins or themes, and achieve server-side code execution. The seller estimates that roughly 100,000 to 300,000 sites could be affected.
The second claimed vulnerability involves Duplicator backup archives. According to the seller, under certain conditions a full backup archive can be downloaded over the web without authentication if its filename is known. Such an archive could potentially contain the entire WordPress installation and a database export, including user accounts, password hashes, configuration data, and other sensitive information.
The third issue is described as an information disclosure vulnerability that makes it easier to determine the filename of a backup archive, thereby amplifying exploitation of the second issue. The seller estimates that tens of thousands of sites could potentially be affected by this scenario.
Duplicator is one of the most popular WordPress plugins for backups, cloning, and site migration. According to the official WordPress.org plugin directory, it has more than 1 million active installations and a rating of 4.9 out of 5.
It is also worth noting that Duplicator has previously been affected by vulnerabilities involving backup exposure. For example, CVE-2022-2551 allowed an unauthenticated attacker, under certain conditions, to obtain the URL of a full site backup. The issue was fixed in Duplicator 1.4.7.
Vulnerabilities
Researchers
Vendors
Products