Sensitive Information Exposure Vulnerability Affects All Versions of All-in-One WP Migration and Backup plugin
CVE-2024-8852
5.3MEDIUM
Key Information:
- Vendor
- All-in-One WP Migration and Backup
- Status
- All-in-one WP Migration
- Vendor
- CVE Published:
- 22 October 2024
Summary
The All-in-One WP Migration and Backup plugin for WordPress presents a vulnerability that exposes sensitive information due to improperly secured log files. This issue allows unauthenticated attackers to potentially gain access to sensitive data such as file paths and other critical system information. The vulnerability affects all versions of the plugin up to and including version 7.86. Website administrators using this plugin should be aware of the risks posed by this exposure and take necessary precautions to secure their WordPress installations.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD Database