The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.
History

Fri, 30 Aug 2024 09:30:00 +0000

Type Values Removed Values Added
Description The BackWPup WordPress plugin before 4.0.4 does not prevent visitors from leaking key information about ongoing backups, allowing unauthenticated attackers to download backups of a site's database. The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-30T09:09:47.349Z

Reserved: 2023-12-28T17:20:48.452Z

Link: CVE-2023-7164

cve-icon Vulnrichment

Updated: 2024-08-02T08:50:08.324Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-08T18:15:08.287

Modified: 2024-11-21T08:45:24.887

Link: CVE-2023-7164

cve-icon Redhat

No data.