Cross-Site Request Forgery in XCloner Backup Plugin for WordPress
CVE-2025-11759
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 December 2025
What is CVE-2025-11759?
The XCloner Backup, Restore and Migrate plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) due to inadequate nonce validation in the Xcloner_Remote_Storage:save() function. This vulnerability allows unauthenticated attackers to exploit forged requests to change or add FTP backup configurations. If an attacker successfully deceives a site administrator into executing a crafted action, they can redirect backup storage to a malicious FTP site. This can result in the exposure of sensitive data, posing a significant security risk to affected WordPress sites.
Affected Version(s)
Backup, Restore and Migrate your sites with XCloner * <= 4.8.2