Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2cmc-mfch-j64j

Опубликовано: 24 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication.

The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication.

EPSS

Процентиль: 33%
0.00129
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
3 месяца назад

The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication.

EPSS

Процентиль: 33%
0.00129
Низкий

5.9 Medium

CVSS3