CVE-2023-7164
HIGHDescription
The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.
Is your site exposed to CVE-2023-7164?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| inpsyde | backwpup |
References
Frequently Asked Questions
What is CVE-2023-7164? +
How severe is CVE-2023-7164? +
What products are affected by CVE-2023-7164? +
How do I check if I'm vulnerable to CVE-2023-7164? +
Related Vulnerabilities
The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the Log …
The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the job-specific …
The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and …