xibodevelopment Vulnerabilities and Affected Products
Vulnerabilities associated with backupwordpress.
Products
Clear product- backupwordpress2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
BackUpWordPress <= 3.13 - Authenticated (Admin+) Directory TraversalThe BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to traverse directories outside of the context in which the plugin should allow. CWE-22Apr 27, 2024 | CVSS2.7v3.1 | EPSS0.65% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2022-4931MEDIUM | BackupWordPress plugin for WordPress heartbeat_received() VulnerabilityThe BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions and above to retrieve back-up paths that can subsequently be used to download the back-up. CWE-862Mar 7, 2023 | CVSS4.3v3.1 | EPSS0.458% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |