Impact
The BackWPup WordPress plugin before version 5.7.7 fails to restrict web access to its working directory during backup restores. An unauthenticated attacker who can reach the site via a web server that does not honor .htaccess rules, such as NGINX, can download the full backup archive left behind after an interrupted restore. The archive contains the database dump and site files, including credentials and secret keys, resulting in a complete exposure of sensitive data.
Affected Systems
BackWPup plugin for WordPress installations running any version earlier than 5.7.7 on web servers like NGINX that ignore .htaccess. Any site using the backup/restore feature therefore is affected.
Risk and Exploitability
The vulnerability allows unauthenticated download of backup artifacts, leading to confidentiality loss. The attack does not require prior authentication and only needs a web request to the working directory. The EPSS score is not available and the vulnerability is not listed in CISA KEV. No CVSS score is provided, but the impact is significant due to complete credential exposure. primary attack vector is web-based, and the conditions are a running BackWPup plugin in a version older than 5.7.7 on a server that allows unrestricted access to the working directory.
OpenCVE Enrichment