5.3

CVE-2023-7232

Exploit

Backup and Restore WordPress WordPress <= 1.45 - Unauthenticated Information Exposure via Log Files

The Backup and Restore WordPress  WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenticated users to access such data
Mögliche Gegenmaßnahme
WP BackItUp Community Edition: Update to version 1.50, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt WP BackItUp Community Edition
Version * - 1.45
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WpbackitupBackup And Restore Wordpress SwPlatformwordpress Version < 1.50
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.541
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N