Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6rrr-pqjc-jxwv

Опубликовано: 19 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-config.php file from the affected site.

The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-config.php file from the affected site.

EPSS

Процентиль: 98%
0.5029
Средний

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
7 месяцев назад

The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-config.php file from the affected site.

EPSS

Процентиль: 98%
0.5029
Средний

7.5 High

CVSS3

Дефекты

CWE-22