Sensitive Information Exposure in WebToffee WordPress Backup & Migration Plugin
CVE-2025-24651

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 April 2025

What is CVE-2025-24651?

A vulnerability exists in the WebToffee WordPress Backup & Migration plugin that allows sensitive information to be embedded in log files. This issue can lead to unintended exposure of confidential data, which could be accessed by unauthorized individuals. The affected versions range from n/a to 1.5.3, emphasizing the importance of securing user data and continuously monitoring plugin updates to mitigate potential risks.

Affected Version(s)

WordPress Backup & Migration <= 1.5.3

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

savphill (Patchstack Alliance)
.