Impact
This vulnerability is a missing authorization flaw that allows attackers to exploit incorrectly configured access control levels in the Everest Backup plugin. An attacker who can trigger the affected functionality could read or download backup files that were intended to be protected, potentially exposing site content, configuration, or user data. The weakness is categorized as CWE‑862, indicating improper authorization controls.
Affected Systems
The vulnerability affects the WordPress Everest Backup plugin from versions n/a through 2.3.8. It is distributed by everestthemes as Everest Backup and is installed via the WordPress plugin repository.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of < 1% suggests that exploitation is unlikely but possible. The vulnerability is not listed in CISA KEV, implying no known widespread exploitation. Based on the description, the likely attack vector involves authenticated users with sufficient role privileges, or potentially any user that can access the plugin’s endpoints. Attackers would need to locate the misplaced access controls or exploit a public route that should be restricted.
OpenCVE Enrichment