Impact
The DB Backup plugin for WordPress contains a missing authorization flaw that allows unsuitable users to view or modify backup data. The weakness is classified as CWE‑862, meaning there is an access‑control failure. Attackers can exploit this by sending requests to protected plugin endpoints and retrieving files or executing administrative actions normally restricted to privileged accounts, thereby compromising confidentiality or integrity of the site.
Affected Systems
The vulnerability affects the WordPress plugin DB Backup (syedamirhussain91) version 6.0 and earlier. Users running any release prior to 6.1 are potentially exposed. No other product versions are known to be impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests a very low probability of exploitation in the wild. The vulnerability is not yet catalogued in the CISA KEV database. Attackers would need to locate the vulnerable plugin endpoint and construct a request that bypasses the intended permission checks; the flaw likely allows unauthenticated or low‑privileged users to elevate privileges within the plugin context.
OpenCVE Enrichment
EUVD