Описание
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Patch
- Exploit
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.2 (исключая)
cpe:2.3:a:wpseeds:wp_database_backup:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 99%
0.78834
Высокий
9.8 Critical
CVSS3
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 9.8
github
7 месяцев назад
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
EPSS
Процентиль: 99%
0.78834
Высокий
9.8 Critical
CVSS3
Дефекты
CWE-78