Impact
The vulnerability is a missing authorization flaw that allows any authenticated user to exploit incorrectly configured access control. The weakness is classed as CWE‑862. Attackers could gain privileged access to backup and move functionality, potentially retrieving or altering backup files, leading to confidentiality and integrity compromises. The impact spans any affected user who can access the plugin interface, as the flaw operates at the application level.
Affected Systems
Gaurav Aggarwal Backup and Move plugin for WordPress, any installation of the plugin through its initial release up to version 0.1 inclusive. No additional product or vendor information is provided.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate severity. The EPSS score of less than 1% indicates low exploit probability at the time of this analysis, and the CVE is not listed in CISA KEV. The likely attack vector is through the plugin’s administrative interface, requiring authentication but not additional user privileges. Without adequate role protections, any authenticated visitor could trigger the vulnerability.
OpenCVE Enrichment