Showing 2 vulnerabilities on this page for backupwordpress

Signals CISA KEV Ransomware Nuclei
xibodevelopment vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

BackUpWordPress <= 3.13 - Authenticated (Admin+) Directory Traversal

The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to traverse directories outside of the context in which the plugin should allow.

CWE-22Apr 27, 2024
CVSS2.7v3.1EPSS0.65%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

BackupWordPress plugin for WordPress heartbeat_received() Vulnerability

The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions and above to retrieve back-up paths that can subsequently be used to download the back-up.

CWE-862Mar 7, 2023
CVSS4.3v3.1EPSS0.458%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX