The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing or incorrect nonce validation on the 'sub' parameter called from the WP STAGING WordPress Backup Plugin - Backup Duplicator & Migration plugin. This makes it possible for unauthenticated attackers to include any local files that end in '-settings.php' via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
History

Wed, 07 Aug 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Wp-staging
Wp-staging wp Staging
Weaknesses CWE-352
CPEs cpe:2.3:a:wp-staging:wp_staging:*:*:*:*:*:wordpress:*:*
Vendors & Products Wp-staging
Wp-staging wp Staging

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-06-14T05:39:14.293Z

Updated: 2024-08-01T21:18:06.505Z

Reserved: 2024-05-30T21:52:21.263Z

Link: CVE-2024-5551

cve-icon Vulnrichment

Updated: 2024-08-01T21:18:06.505Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-14T06:15:13.443

Modified: 2024-08-07T19:09:17.363

Link: CVE-2024-5551

cve-icon Redhat

No data.