Showing 2 vulnerabilities on this page for backwpup

Signals CISA KEV Ransomware Nuclei
Inpsyde vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

BackWPup < 4.0.4 - Unauthenticated Backup Download

The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.

CWE-548Apr 8, 20241 related artifact
CVSS7.5v3.1EPSS2.26%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.

CWE-552Sep 27, 2017
CVSS7.5v3.0EPSS1.67%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX