CVE-2023-7164
BackWPup < 4.0.4 - Unauthenticated Backup Download
Record summary
CVE-2023-7164 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 20, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
BackWPupDefault status: unaffected | CVE List | Before 4.0.4 | affected |
backwpupBrowse inpsyde / backwpupDefault status: unknown | CVE List | Before 4.0.4 | affected |
Nuclei templates
1ProjectDiscoveryHIGHWordPress BackWPup < 4.0.4 - Backup File DisclosureCVSS 7.5
BackWPup WordPress plugin < 4.0.4 contains a directory listing vulnerability caused by lack of access restrictions in its temporary backup folder, letting unauthenticated attackers download site backups, exploit requires no authentication.
Impact
Unauthenticated attackers can download site backups, potentially leading to data theft or further exploitation.
Remediation
Update to version 4.0.4 or later.
Source: ProjectDiscovery