Unauthorized Data Access in WordPress Backup & Migration Plugin
CVE-2024-3546

4.3MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
2 May 2024

Summary

The WordPress Backup & Migration plugin has a vulnerability that permits unauthorized access to sensitive log files, caused by a lack of capability checks in the wp_mgdp_populate_popup function. Authenticated attackers with subscriber privileges or higher can exploit this issue to retrieve log files that the plugin maintains. Additionally, the file name provided by users is not adequately sanitized, allowing attackers to read potentially sensitive arbitrary files from the server's file system. This flaw poses significant risks to the confidentiality of data handled by the plugin, demanding immediate attention from users to secure their installations.

Affected Version(s)

WordPress Backup & Migration * <= 1.4.8

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Zając
.