Impact
The BackWPup plugin for WordPress, versions before 5.7.5, contains a missing authorization check on several REST API routes that manage job, backup‑destination, and backup‑execution resources. This flaw allows any user assigned a BackWPup‑defined limited role to create and trigger backup jobs and to download the resulting database backup to an attacker‑controlled destination. The impact is a full confidentiality breach, as an attacker can obtain the entire database without needing higher‑privilege credentials.
Affected Systems
BackWPup WordPress plugin, versions 5.2.2 through 5.7.4, are affected. Users running any of these versions on their WordPress sites must consider this vulnerability.
Risk and Exploitability
The vulnerability is exploitable via the web‑based REST API and requires an authenticated user with the limited BackWPup role. Because the attack vector is a documented REST endpoint, the probability of remote exploitation is non‑zero, but the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 5.5 indicates a moderate severity, but the potential for unrestricted database exfiltration still warrants immediate action.
OpenCVE Enrichment