WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More

The best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy, move, or clone your site from one location to another.

14Reported vulnerabilities
9.8Highest CVSS score
1.5.16.1Latest version
1,000,000+Active installs

What to do now

Update Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More to 1.5.10 or later. 14 of these have a fixed version available. Updating resolves them.

Plugin last updated: May 22, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2018-17207 Critical 9.8 60.1% 1.2.40 and earlier 1.2.42 August 29, 2018
CVE-2023-6114 High 7.5 30.9% Before 1.5.7.1 1.5.7.1 December 26, 2023
CVE-2022-2551 Critical 9.8 16.7% 1.4.7 and earlier 1.4.7.1 July 27, 2022
CVE-2014-9262 High 8.2 7.5% 0.5.8 and earlier 0.5.10 August 7, 2017
CVE-2018-25095 Critical 9.8 0.9% 0 up to (but not including) 1.3.0 1.3.0 January 8, 2024
CVE-2022-2552 Medium 5.3 11.3% 0 up to (but not including) 1.4.7 1.4.7 August 22, 2022
CVE-2013-4625 Medium 6.1 11.1% 0.4.4 and earlier 0.4.5 August 1, 2014
WF-3762cd92-604a-4dac-a09e-6b4a08c4d804 High 8.8 0.5.14 and earlier 0.5.16 April 10, 2015
CVE-2018-7543 Medium 6.1 3.3% 1.2.32 and earlier 1.2.33 March 15, 2018
CVE-2023-51681 Medium 6.5 0.3% 1.5.7 and earlier 1.5.7.1 February 28, 2024
CVE-2017-16815 Medium 6.1 1.0% 1.2.28 to 1.2.28 (inclusive) 1.2.30 November 14, 2017
WF-3f753961-3eeb-402d-876f-4a4dea41a96a Medium 6.5 Before 1.1.4 1.1.4 February 9, 2016
CVE-2024-6210 Medium 5.3 0.6% 0 to 1.5.9 (inclusive)
0 to 1.5.9 (inclusive)
1.5.10 July 11, 2024
WF-06905738-7e1c-4d1a-97d2-f68f978ad8ed Medium 5.5 Before 0.5.28 0.5.28 August 15, 2015

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.