Impact
Untrusted access to backup files allows an attacker to view sensitive information without authentication. The flaw permits reading backup data stored by the BackupEase plugin, potentially revealing passwords, database contents, or personal data. It is a classic instance of CWE‑201, which compromises confidentiality.
Affected Systems
The vulnerability affects WordPress sites using the PrecisionWP BackupEase plugin version 2.2.2 or earlier. System administrators should check that no older versions are deployed.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. Because the attack vector is unauthenticated, any user who can reach the backup location could exploit it. The EPSS score is not available, but the lack of a KEV listing suggests no known widespread exploitation yet. Nevertheless, the potential for large-scale data exposure warrants prompt remediation.
OpenCVE Enrichment