Record summary

CVE-2023-6750 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 4, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Clone

Default status: unaffected

CVE ListBefore 2.4.3affected

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress WP Clone <= 2.4.2 - Database Backup ExposureCVSS 9.8

Clone WordPress plugin < 2.4.3 contains a buffer overflow caused by storing in-progress backup information in publicly accessible buffer files at a static file path, letting attackers access sensitive backup data, exploit requires no special privileges

Impact

Attackers can access sensitive backup information, potentially leading to data disclosure or manipulation.

Remediation

Update to version 2.4.3 or later.

WeaknessesCWE-200
Authorspussycat0x
Template tagscvecve2023wpwp-pluginwordpresswp-clonebackup
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:developer:clone:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"wp-clone-by-wp-academy"
FOFA: body="wp-clone-by-wp-academy"

Source: ProjectDiscovery

References

2