Impact
The JetBackup plugin for WordPress fails to perform a proper multisite authorization check before serving backup archives and job logs. This flaw allows a network administrator who is not a Super Admin to download a complete backup of the entire network, potentially revealing sensitive content from all sites and the shared webroot. The breach results in a confidentiality compromise and could facilitate further compromise if the backup contains configuration files or credentials.
Affected Systems
JetBackup on WordPress multisite installations, versions 3.1.18.8 through 3.1.23.3, are affected. Any site that uses the plugin in this range is vulnerable.
Risk and Exploitability
The vulnerability is exploitable by individuals with network admin rights but not super admin rights, a common role in larger organisations. The CVSS score of 4.4 indicates moderate severity, and the EPSS score of < 1% suggests a low likelihood of exploitation, and it is not listed in the CISA KEV catalog. If an attacker can leverage the privileged network admin role, they can download a full backup of the entire network with minimal effort, which could expose sensitive data and compromise confidentiality.
OpenCVE Enrichment