The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.13 via the exposed process stats file during the backup process. This makes it possible for unauthenticated attackers to obtain an archive file name and download the site's backup.
History

Wed, 06 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Everestthemes
Everestthemes everest Backup
CPEs cpe:2.3:a:everestthemes:everest_backup:*:*:*:*:*:wordpress:*:*
Vendors & Products Everestthemes
Everestthemes everest Backup
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 05 Nov 2024 23:45:00 +0000

Type Values Removed Values Added
Description The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.13 via the exposed process stats file during the backup process. This makes it possible for unauthenticated attackers to obtain an archive file name and download the site's backup.
Title Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.2.13 - Sensitive Invormation Disclosure via procstat Log
Weaknesses CWE-922
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-11-05T23:28:42.426Z

Updated: 2024-11-06T15:11:04.780Z

Reserved: 2024-10-16T10:28:55.295Z

Link: CVE-2024-10028

cve-icon Vulnrichment

Updated: 2024-11-06T15:10:59.783Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-06T00:15:13.000

Modified: 2024-11-08T21:21:47.240

Link: CVE-2024-10028

cve-icon Redhat

No data.