Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

WordPress Plugin Duplicator Pro Allows Remote Code Execution

ECHO-8d16-7d9a-2e99
Summary

The Duplicator Pro plugin for WordPress has a vulnerability that could allow an attacker to execute malicious code on a website. This means a hacker could potentially take control of a site by exploiting this flaw. WordPress website owners who use Duplicator Pro should update to the latest version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
libraw All versions
Original title
ECHO-8d16-7d9a-2e99
Published: 8 Apr 2026 · Updated: 8 Apr 2026 · First seen: 8 Apr 2026