Impact
The vulnerability in the Swish Migrate and Backup plugin allows unauthenticated attackers to read sensitive data that the plugin stores or backs up. The flaw stems from insufficient access controls, which permits exposure of confidential information that the plugin handles. Attackers can compromise the confidentiality of data stored on the WordPress site, such as private configurations, backup files, or sensitive customer information.
Affected Systems
The affected product is Swish Migrate and Backup by SwishFolio. Versions up to and including 1.4.0 are impacted. No other products or versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.9 rates this flaw as medium severity, indicating a non-trivial risk to data confidentiality. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the web application layer, with unauthenticated users able to trigger the exposure. Because the flaw operates without authentication, any visitor to the site could potentially abuse it if the vulnerable plugin is installed.
OpenCVE Enrichment