Access Control Vulnerability in wp-db-backup Plugin for WordPress
CVE-2014-10076

7.5HIGH

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
5 October 2018

What is CVE-2014-10076?

The wp-db-backup plugin version 2.2.4 for WordPress contains an access control vulnerability due to its reliance on a simple five-character string for authorization. This weakness can be exploited by remote attackers, who can perform brute-force attacks to gain unauthorized access and read sensitive backup archives. Such access can lead to the exposure of sensitive data, thereby compromising the security of the entire WordPress site.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.