nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-3132 CVE-2023-3132
MEDIUM
MainWP Child <= 4.4.1.1 - Information Disclosure via Back-Up Files
Record summary
CVE-2023-3132 has a selected CVSS score of 5.9 (medium).
Description
The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient controls on the storage of back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including the entire installations database if a backup occurs and the deletion of the back-up files fail.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 6, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple SitesBrowse mainwp / MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple SitesDefault status: unaffected | CVE List | Through 4.4.1.1 | affected |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2923512%40mainwp-child&new=2923512%40mainwp-child&sfp_email=&sfph_mail= wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/a1fadba1-674f-4f3d-997f-d29d3a887414?source=cve