Executive brief
XCloner, a popular WordPress plugin used for site backups and restoration, contains a security flaw that exposes sensitive information. This vulnerability allows users with low-level 'Subscriber' accounts to access data that should be restricted to administrators. An attacker could use this information to gain deeper access to the website or compromise user privacy.
Technical details
XCloner versions 4.8.6 and earlier are vulnerable to sensitive data exposure (CWE-201). The vulnerability allows an authenticated user with Subscriber-level privileges to access sensitive information that is normally restricted to higher-level roles. This occurs due to improper access controls or the inadvertent inclusion of sensitive data in responses sent to the client. Attackers can leverage this exposure to facilitate further attacks against the WordPress environment. The issue is resolved in version 4.8.7.
Affected products
- XCloner XCloner - Backup and Restore <= 4.8.6
Timeline
- 2026-04-23: other: Reported by kai63001
- 2026-06-03: patched: Version 4.8.7 released
- 2026-06-15: disclosed: NVD publication date