Impact
An unauthenticated Cross Site Scripting vulnerability exists in WordPress BackWPup plugin versions 5.7.4 and earlier. The flaw allows an attacker to inject arbitrary client‑side scripts into the web interface. The weakness is a classic input validation problem identified as CWE‑79.
Affected Systems
The affected product is the WP Media BackWPup WordPress plugin. Versions up to and including 5.7.4 are vulnerable; all releases 5.7.5 and newer contain a fix.
Risk and Exploitability
The CVSS base score is 7.1, indicating a high severity. The EPSS score is < 1%, suggesting a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the flaw can be exploited from any web‑connected client that can access the vulnerable plugin’s input fields, as authentication is not required. An attacker may inject malicious scripts into these fields, causing client‑side code to execute in the victim’s browser.
OpenCVE Enrichment