CVE-2013-2743

BackupBuddy 1.3.4, 2.1.4, 2.2.25, 2.2.28, 2.2.4 - Unauthenticated Authentication Bypass via Step Parameter

Title source: llm
STIX 2.1

Description

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via a crafted integer in the step parameter.

References (2)

Core 2
Core References

Scores

EPSS 0.0256
EPSS Percentile 83.1%

Details

CWE
CWE-287
Status published
Products (5)
ithemes/backupbuddy 1.3.4
ithemes/backupbuddy 2.1.4
ithemes/backupbuddy 2.2.4
ithemes/backupbuddy 2.2.25
ithemes/backupbuddy 2.2.28
Published Apr 02, 2013
Tracked Since Feb 18, 2026