Backuply Plugin Vulnerable to Denial of Service Attacks
CVE-2024-0842

7.5HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
9 February 2024

Summary

The Backuply plugin for WordPress, designed for backup and migration tasks, exhibits a vulnerability that allows unauthenticated attackers to exploit the backuply/restore_ins.php file. This vulnerability enables attackers to send excessive requests to the server, potentially leading to resource depletion and service disruption. All versions up to and including 1.2.5 are affected, underscoring the need for immediate action to secure user environments and mitigate potential risks associated with this vulnerability.

Affected Version(s)

Backuply – Backup, Restore, Migrate and Clone * <= 1.2.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Villu Orav
.