Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-10134

Опубликовано: 19 июл. 2025
Источник: nvd
CVSS3: 7.5
EPSS Средний

Описание

The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-config.php file from the affected site.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mywebsiteadvisor:simple_backup:*:*:*:*:*:wordpress:*:*
Версия до 2.7.10 (включая)

EPSS

Процентиль: 98%
0.5029
Средний

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
github
7 месяцев назад

The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-config.php file from the affected site.

EPSS

Процентиль: 98%
0.5029
Средний

7.5 High

CVSS3

Дефекты

CWE-22