Impact
The vulnerability is an unauthenticated sensitive data exposure in the StifLi Backup Tools plugin up to and including version 2.2.7. An attacker can obtain confidential information without authentication, which violates the principles of confidentiality and privacy. The weakness maps to CWE‑201.
Affected Systems
The affected product is the Esteban StifLi Backup Tools WordPress plugin, versions 2.2.7 and earlier. All WordPress sites running a vulnerable version are at risk. No specific operating system or environment limitations are noted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity impact. Because EPSS information is not available, the probability of exploitation is unknown, but the vulnerability is publicly known and referenced in multiple advisories. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is any unauthenticated request to the plugin’s exposed functionality, allowing an attacker to retrieve sensitive data.
OpenCVE Enrichment