5.3

CVE-2023-7232

Exploit

Backup and Restore WordPress <= 1.45 - Unauthenticated Sensitive Data Exposure

Backup and Restore WordPress WordPress <= 1.45 - Unauthenticated Information Exposure via Log Files

The Backup and Restore WordPress  WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenticated users to access such data
Mögliche Gegenmaßnahme
WP BackItUp Community Edition: Update to version 1.50, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WpbackitupBackup And Restore Wordpress SwPlatformwordpress Version < 1.50
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt WP BackItUp Community Edition
Version *-1.45
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.424
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/323fef8a-aa17-4698-9a02-c12d1d390763/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/6db51b8e-2e4b-4041-b261-d46cfdb372dc
Third Party Advisory