Impact
JetBackup’s WordPress backup plugin fails to verify the role or capabilities of a user when a backup is restored or the site is migrated. As a result, a user with only subscriber-level privileges can gain administrator access upon restoration, effectively escalating privileges without authorization. The flaw directly allows a lower‑privileged user to attain full control over the website content, settings, and other user accounts.
Affected Systems
WordPress sites running the JetBackup plugin version 3.1.7.9 through 3.1.23.3 are impacted. The vendor is listed as Unknown:JetBackup. All affected instances lack the role‑verification logic that assigns only existing administrators elevated rights during a restore or migration.
Risk and Exploitability
Exploit requires the site owner or a person with restoration privileges to initiate a backup restore or migration on a site that contains a subscriber user. When the restore occurs, the plugin incorrectly assigns administrator privileges to that subscriber. The EPSS score of < 1% indicates a very low probability of exploitation, yet the vulnerability is not listed in CISA KEV. The CVSS score of 7.1 indicates medium‑high severity, but the vulnerability poses a significant threat due to the clear privilege escalation path and the ease of exploitation during routine restoration tasks. Attackers would need to reach a state where the site owner performs the restore, after which the subscriber becomes an administrator automatically.
OpenCVE Enrichment