Information Disclosure Vulnerability in Total Upkeep Plugin for WordPress
CVE-2022-4932
4.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 7 March 2023
Summary
The Total Upkeep plugin for WordPress is susceptible to an information disclosure vulnerability that allows authenticated attackers, with subscriber-level permissions or higher, to access sensitive backup paths. This issue arises from insufficient authorization in the heartbeat_received() function, triggered by WordPress heartbeats. Exploiting this vulnerability could enable attackers to download critical backup files, potentially compromising the integrity and confidentiality of the site's data.
Affected Version(s)
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid * <= 1.14.13
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Chloe Chamberland