nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-36668 CVE-2020-36668
MEDIUM
JetBackup – WP Backup, Migrate & Restore <= 1.4.0 - Sensitive Information Disclosure
Record summary
CVE-2020-36668 has a selected CVSS score of 4.3 (medium).
Description
The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and including, 1.4.0 due to a lack of proper capability checking on the backup_guard_get_manual_modal function called via an AJAX action. This makes it possible for subscriber-level attackers, and above, to invoke the function and obtain database table information.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 30, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 13, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
JetBackup – Backup, Restore & MigrateBrowse backupguard / JetBackup – Backup, Restore & MigrateDefault status: unaffected | CVE List | Through 1.4.0 | affected |
jetbackupBrowse jetbackup / jetbackup | VulnCheck | Version data not supplied | |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2348984%40backup&new=2348984%40backup&sfp_email=&sfph_mail= wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/3e2a9d71-21ef-45a1-99ed-477066ce9620 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/3e2a9d71-21ef-45a1-99ed-477066ce9620?source=cve