Impact
The vulnerability is a failure of proper access controls that permits any unauthenticated user to retrieve sensitive data stored by the WordPress ZHBackup – Backup, Restore & Migration Plugin. The flaw arises from insufficient verification of user credentials before disclosing backup archives or configuration information, which can lead to the disclosure of confidential data such as passwords, encryption keys, and personal user information. This weakness is classified as CWE‑201: Sensitive Information Exposure, and the potential impact is the loss of confidentiality of data that was intended to be protected or only accessible by authorized administrators.
Affected Systems
WordPress sites that use Zain Hassan’s ZHBackup – Backup, Restore & Migration Plugin version 2.4.2 or earlier are impacted. The plugin is the sole product identified by the CNA and is affected across all environments where it is deployed without upgrade.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be exploited by accessing the plugin’s backup endpoints without authentication, an attacker could obtain sensitive data remotely. The lack of an EPSS value means that the current quantified likelihood of exploitation is unknown, but the high CVSS score and open web access increase the practical risk for exposed installations.
OpenCVE Enrichment