Impact
The WP BackItUp Community Edition plugin contains a directory traversal flaw in the backup_file parameter. An attacker who has administrator privileges or higher can craft a request that includes path traversal sequences, resulting in the plugin reading the contents of any file that exists on the server. This flaw allows the attacker to expose sensitive information located in server files, including configuration, database credentials, or personal user data, thereby compromising confidentiality. The weakness is a classic file system traversal (CWE-22).
Affected Systems
All WordPress installations that use WP BackItUp Community Edition version 2.1.0 or earlier are affected. Any site running a vulnerable plugin version is susceptible if an administrator account can be accessed.
Risk and Exploitability
The CVSS score is 4.9, indicating moderate risk. No EPSS score is supplied and the vulnerability is not listed in CISA's KEV catalog. An attacker must already have authenticated administrator access to exploit the flaw. Because the attacker can read arbitrary existing files, the severity depends on the sensitivity of the files available on the host but the overall impact remains moderate as authenticated access can be limited in many environments. The exploitation requires only the misuse of the backup_file endpoint and no external network entry point beyond normal WordPress administrative traffic.
OpenCVE Enrichment