CVE-2014-2340: Xcloner

Medium severity, CVSS 6.8. EPSS: 2.8% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php.

Affected products

  • Xcloner Xcloner: up to and including 3.1.0; version 2.1 only; version 2.1.2 only; version 2.2.1 only; version 3.0 only; version 3.0.1 only; …

Published 2014-04-03. Last modified 2026-06-17.