Information Disclosure in Backup Migration Plugin for WordPress
CVE-2023-54346
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 May 2026
Badges
What is CVE-2023-54346?
The Backup Migration Plugin version 1.2.8 for WordPress is vulnerable to information disclosure that enables unauthenticated attackers to access sensitive database backups. By exploiting predictable file paths, attackers can enumerate backup directories using configuration files and logs. This vulnerability allows them to craft direct download URLs, thereby retrieving full database dumps that may contain critical user data and configurations.
Affected Version(s)
WordPress Plugin Backup Migration 1.2.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved