Information Disclosure Vulnerability in Total Upkeep Plugin for WordPress
CVE-2022-4932

4.3MEDIUM

Key Information:

Summary

The Total Upkeep plugin for WordPress is susceptible to an information disclosure vulnerability that allows authenticated attackers, with subscriber-level permissions or higher, to access sensitive backup paths. This issue arises from insufficient authorization in the heartbeat_received() function, triggered by WordPress heartbeats. Exploiting this vulnerability could enable attackers to download critical backup files, potentially compromising the integrity and confidentiality of the site's data.

Affected Version(s)

Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid * <= 1.14.13

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chloe Chamberland
.