Описание
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Patch
- Exploit
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.2 (исключая)
cpe:2.3:a:wpseeds:wp_database_backup:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 97%
0.16682
Средний
9.8 Critical
CVSS3
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 9.8
github
около 1 года назад
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
EPSS
Процентиль: 97%
0.16682
Средний
9.8 Critical
CVSS3
Дефекты
CWE-78