CVE-2023-6750
Clone < 2.4.3 - Unauthenticated Backup Download
Record summary
CVE-2023-6750 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 4, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CloneDefault status: unaffected | CVE List | Before 2.4.3 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALWordPress WP Clone <= 2.4.2 - Database Backup ExposureCVSS 9.8
Clone WordPress plugin < 2.4.3 contains a buffer overflow caused by storing in-progress backup information in publicly accessible buffer files at a static file path, letting attackers access sensitive backup data, exploit requires no special privileges
Impact
Attackers can access sensitive backup information, potentially leading to data disclosure or manipulation.
Remediation
Update to version 2.4.3 or later.
Source: ProjectDiscovery