• Design
  • SEO
  • Portfolio
  • Why Choose Us
  • Blog
  • Contact
  • Facebook
  • Google+
Precise Online ManagementPrecise Online Management
  • Design
  • SEO
  • Portfolio
  • Why Choose Us
  • Blog
  • Contact
  • Facebook
  • Google+

Popular WordPress plugin patches recently discovered vulnerability

Duplicator Plugin

Popular WordPress plugin patches recently discovered vulnerability

September 19, 2018 News, Security

News Courtesy of ZDNet.com:

The vulnerability affects “Duplicator,” a WordPress plugin that’s installed on over one million sites, according to statistics listed on the official WordPress Plugins directory. The plugin is popular because it allows site admins migrate sites to new servers within minutes.

Duplicator works by generating a ZIP file containing the previous version of the site, along with a PHP file named installer.php. All a site admin has to do is to upload the ZIP archive and a file named installer.php on the new server, access the PHP file, enter new database credentials, and have the new site up and running.

– Read Source Article

Ryan’s Take

As popular as Duplicator is, I’ve never used yet on the dozens of websites I’ve migrated from or to my server over my career. I’ve had great success with both All-in-One WP Migration and Backup Guard for moving websites. They each offer a premium version, however, I’ve had no problems using the free options for either. At some point, I plan to purchase one of them with a developer license, since there is a little extra legwork required for importing databases into the new server.

The “vulnerability” with Duplicator shouldn’t rest solely on the developer’s shoulders. The main issue pertains to a zip file and php file that aren’t deleted after a completed migration. As a server administrator, I believe it is part of my job to clean up any mess or unused files that are generated by a theme or plugin. To make the assumption that Duplicator will perform that operation is a little presumptuous. A good admin should routinely clear out any anything such as cache and installation files.

If you do use Duplicator, don’t stress out. The latest version patches this issue. It is odd that this is just being discovered now, or at least made public. There will be, no doubt, a continued barrage of hijacking attempts by hackers that find websites with duplicator installed. I remember a few years ago when a huge Revolution Slider exploit wreaked havoc across the internet and caused many sites to be defaced or infected with spam/malware. To this day, I still see failed attempts by these punks trying to upload revslider.zip. Unfortunately, with the rising popularity of WordPress, it’s only natural that exploits will be increasing as well.

0 0 votes
Article Rating
Share
0

About Ryan Faucher

Owner-operator of Precise Online Management. I also manage Kettlebell Krusher, a website dedicated to all things kettlebell as well a blog for my weight loss progress.

Subscribe
Notify of
guest
guest
0 Comments
Inline Feedbacks
View all comments

Categories

  • News
  • Niche Dreams
  • Reviews
  • Security
  • SEO
  • Tips

Recent Posts

  • 9 Benefits of Social Media for Your Organization
  • Advantages of Having Marketing Research Samples
  • Link Building Services: How To Find A Trustworthy Provider
  • SAS Affiliate Review and Tips for Affiliate Marketers
  • Comparison Of The Best Link Indexing Service Features & Benefits

Archives

  • January 2022
  • January 2021
  • October 2020
  • September 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
Ready to get started? Pick and choose your website and / or SEO services Order Services

© 2025 · Precise Online Management, LLC.
This site is owned and operated by Ryan Faucher

  • Visit Us on Facebook
  • Visit Us On Google+
Prev Next
wpDiscuz
X
WEB DESIGN SPECIAL PRICING - Over 60% off design packages through Fiverr
See Details