Lucene search

K
wpvulndbWpvulndbWPVDB-ID:E96721FC-64E3-4D5F-B669-DD549603A50B
HistoryFeb 06, 2024 - 12:00 a.m.

Total Upkeep < 1.15.9 - Improper Authorization to Unauthenticated Arbitrary File Download

2024-02-0600:00:00
wpscan.com
16
total upkeep
wordpress backup plugin
boldgrid
improper authorization
unauthorized access
data
vulnerability
unauthenticated attackers
arbitrary files
cli functionality
software

AI Score

7.1

Confidence

High

EPSS

0

Percentile

10.5%

Description The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check in all versions up to, and including, 1.15.8. This makes it possible for unauthenticated attackers to download arbitrary files using the plugin’s CLI functionality.

AI Score

7.1

Confidence

High

EPSS

0

Percentile

10.5%

Related for WPVDB-ID:E96721FC-64E3-4D5F-B669-DD549603A50B