WP Staging (Free < 3.1.3, Pro < 5.1.3) - Unauthenticated Backup Download
CVE-2023-6113
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 1 January 2024
Badges
Summary
The WP STAGING WordPress Backup Plugin and its Pro version are susceptible to a critical vulnerability that allows unauthorized users to access ongoing backup processes. This exposure can lead to sensitive data being downloaded by unauthenticated attackers, posing significant risks to the information integrity of WordPress sites. Users of affected versions are strongly advised to update to the latest releases to mitigate these risks.
Affected Version(s)
WP STAGING Pro WordPress Backup Plugin 0 < 5.1.3
WP STAGING WordPress Backup Plugin 0 < 3.1.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved