Backuply Plugin Vulnerable to Denial of Service Attacks
CVE-2024-0842
7.5HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 9 February 2024
Summary
The Backuply plugin for WordPress, designed for backup and migration tasks, exhibits a vulnerability that allows unauthenticated attackers to exploit the backuply/restore_ins.php file. This vulnerability enables attackers to send excessive requests to the server, potentially leading to resource depletion and service disruption. All versions up to and including 1.2.5 are affected, underscoring the need for immediate action to secure user environments and mitigate potential risks associated with this vulnerability.
Affected Version(s)
Backuply – Backup, Restore, Migrate and Clone * <= 1.2.5
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Villu Orav