Impact
Missing Authorization in the WP BackItUp plugin for WordPress allows attackers to bypass configured access control settings. An attacker can exploit wrongly set security levels to gain unauthorized access to plugin features, potentially exposing backup data, administrative functions, or other sensitive information. The core weakness is a broken access control flaw (CWE-862).
Affected Systems
The vulnerability affects the WP BackItUp plugin developed by Chris Simmons. All installations running version 2.1.0 or earlier are impacted; the issue is present from the earliest release through 2.1.0 inclusive. Vulnerable systems include WordPress sites where the plugin is installed and configured without proper role restrictions.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. It is likely exploitable via the web interface of the plugin, though the description does not provide explicit exploitation details. Attackers would need access to the WordPress site’s administration area or to craft requests that bypass role checks to take advantage of this flaw.
OpenCVE Enrichment