A cross-site scripting vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.
id: CVE-2013-4625
info:
name: WordPress Plugin Duplicator < 0.4.5 - Cross-Site Scripting
author
...