Authorization Flaw in Azzaroco WP SuperBackup Plugin
CVE-2024-56070

7.4HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
31 December 2024

What is CVE-2024-56070?

An access control vulnerability in Azzaroco WP SuperBackup allows unauthorized exploitation due to incorrectly configured security levels. This configuration issue can lead to unauthorized users gaining access to sensitive functionalities within the plugin, potentially compromising site integrity. Versions from n/a up to 2.3.3 are particularly vulnerable, making it crucial for users to review their security settings and implement necessary updates to safeguard their WordPress installations.

Affected Version(s)

WP SuperBackup <= 2.3.3

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dave Jong (Patchstack)
.