Cross-Site Request Forgery in JetBackup Plugin for WordPress
CVE-2020-36669
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 March 2023
What is CVE-2020-36669?
The JetBackup β WP Backup, Migrate & Restore plugin for WordPress contains a Cross-Site Request Forgery (CSRF) vulnerability in versions up to 1.3.9. This vulnerability arises from inadequate nonce validation on the backup_guard_get_import_backup() function. It allows unauthenticated attackers to potentially upload arbitrary files to the server of the targeted site if they can trick an administrator into executing a malicious request, such as clicking on a compromised link.
Affected Version(s)
JetBackup β Backup, Restore & Migrate 0 <= 1.3.9