CVE-2014-8604: Xcloner

Medium severity, CVSS 5.0. EPSS: 6.9% chance of exploitation in the next 30 days.

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obtain sensitive information via unspecified vectors.

Affected products

  • Xcloner Xcloner: version 3.1.1 only; version 3.5.1 only

Published 2015-06-10. Last modified 2026-06-17.