Impact
The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to craft a request that performs path traversal and deletes arbitrary files on the WordPress site. An exploit would enable the attacker to remove critical files, potentially disrupting site functionality or enabling further compromise. The weakness is classified as CWE‑352.
Affected Systems
The affected product is the WordPress Backwp plugin from wphobby. All releases up to and including version 2.0.2 are vulnerable. No specific sub‑versions are listed, so any installation of the plugin at or below 2.0.2 is at risk.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity, while the EPSS score of less than 1% suggests low-to‑moderate likelihood of exploitation as of the last analysis. The vulnerability is not listed in the CISA KEV catalog. Because the flaw is exploitable via a CSRF attack, it requires that an authenticated user visit a malicious page or that the attacker can otherwise influence the victim’s browser to send a request. If successful, the attacker could delete arbitrary files, resulting in loss of data, site downtime, or an easier path to further compromise the site.
OpenCVE Enrichment
EUVD