Sensitive Information Disclosure in JetBackup Plugin for WordPress
CVE-2020-36668
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 March 2023
What is CVE-2020-36668?
The JetBackup β WP Backup, Migrate & Restore plugin for WordPress is susceptible to sensitive information disclosure due to inadequate capability checks within the backup_guard_get_manual_modal AJAX action. This vulnerability allows attackers with subscriber-level access or higher to invoke the function, resulting in unauthorized access to sensitive database table information.
Affected Version(s)
JetBackup β Backup, Restore & Migrate 0 <= 1.4.0