Unauthorized Backup Location Changes in JetBackup Plugin for WordPress
CVE-2020-36667
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 March 2023
What is CVE-2020-36667?
The JetBackup – WP Backup, Migrate & Restore plugin for WordPress contains a vulnerability that enables authenticated attackers to alter backup locations. This security issue arises from inadequate capability checks in the plugin’s backup_guard_cloud_dropbox, backup_guard_cloud_gdrive, and backup_guard_cloud_oneDrive functions. As a result, attackers with minimal permissions—such as a subscriber—can reroute backups to unauthorized locations, leading to potential data exposure or theft of sensitive information.
Affected Version(s)
JetBackup – Backup, Restore & Migrate 0 <= 1.4.0