nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-4931 CVE-2022-4931
MEDIUM
BackupWordPress plugin for WordPress heartbeat_received() Vulnerability
Record summary
CVE-2022-4931 has a selected CVSS score of 4.3 (medium).
Description
The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions and above to retrieve back-up paths that can subsequently be used to download the back-up.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 7, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 13, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
BackUpWordPressBrowse willmot / BackUpWordPressDefault status: unaffected | CVE List | 3.12 | affected |
backupwordpressBrowse xibodevelopment / backupwordpress | VulnCheck | Version data not supplied | |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2683799%40backupwordpress&new=2683799%40backupwordpress&sfp_email=&sfph_mail= wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/747c86f4-118b-4a9c-899c-e9067d2c7a02