4.3
CVE-2024-3546
- EPSS 0.31%
- Veröffentlicht 02.05.2024 17:15:26
- Zuletzt bearbeitet 21.11.2024 09:29:50
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
WordPress Backup & Migration <= 1.4.8 - Missing Authorization to Directory Traversal
The WordPress Backup & Migration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wp_mgdp_populate_popup function in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with subscriber access or above, to invoke this function and access log files maintained by the plugin. Additionally, the file name is user-provided and not properly sanitized, which allows attackers to read arbitrary log files on the file system.
Mögliche Gegenmaßnahme
WebToffee WP Backup and Migration: Update to version 1.4.9, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WebToffee WP Backup and Migration
Version
* - 1.4.8
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellerwebtoffee
≫
Produkt
backup_and_migration
Default Statusunknown
Version <=
1.4.8
Version
0
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.534 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|