Inpsyde Vulnerabilities and Affected Products
Vulnerabilities associated with backwpup.
Products
Clear product- backwpup2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-7164HIGH | BackWPup < 4.0.4 - Unauthenticated Backup DownloadThe BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database. | CVSS7.5v3.1 | EPSS2.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2017-2551HIGH | Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download. CWE-552Sep 27, 2017 | CVSS7.5v3.0 | EPSS1.67% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |