Record summary

CVE-2023-7164 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 20, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

BackWPup

Default status: unaffected

CVE ListBefore 4.0.4affected

Default status: unknown

CVE ListBefore 4.0.4affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress BackWPup < 4.0.4 - Backup File DisclosureCVSS 7.5

BackWPup WordPress plugin < 4.0.4 contains a directory listing vulnerability caused by lack of access restrictions in its temporary backup folder, letting unauthenticated attackers download site backups, exploit requires no authentication.

Impact

Unauthenticated attackers can download site backups, potentially leading to data theft or further exploitation.

Remediation

Update to version 4.0.4 or later.

WeaknessesCWE-200
Authors0x_Akoko
Template tagscvecve2023wpwordpresswp-pluginbackwpupexposuredisclosure
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:inpsyde:backwpup:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/backwpup/"

Source: ProjectDiscovery

References

2