Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-3132
HistoryJun 27, 2023 - 3:15 a.m.

Arbitrary file deletion

2023-06-2703:15:00
PRIOn knowledge base
www.prio-n.com
1
wordpress
mainwp child
sensitive information exposure
backup files
database

7.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.1%

The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient controls on the storage of back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including the entire installations database if a backup occurs and the deletion of the back-up files fail.

CPENameOperatorVersion
mainwp_childle4.4.1.1

7.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.1%

Related for PRION:CVE-2023-3132