Unauthorized Data Access in WordPress Backup & Migration Plugin
CVE-2024-3546
4.3MEDIUM
Summary
The WordPress Backup & Migration plugin has a vulnerability that permits unauthorized access to sensitive log files, caused by a lack of capability checks in the wp_mgdp_populate_popup function. Authenticated attackers with subscriber privileges or higher can exploit this issue to retrieve log files that the plugin maintains. Additionally, the file name provided by users is not adequately sanitized, allowing attackers to read potentially sensitive arbitrary files from the server's file system. This flaw poses significant risks to the confidentiality of data handled by the plugin, demanding immediate attention from users to secure their installations.
Affected Version(s)
WordPress Backup & Migration * <= 1.4.8
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Krzysztof Zając