Backup Migration <= 1.2.8 - Sensitive Information Exposure

2023-05-10 00:00
Wadeek

Strategic Overview

Status
Patched in 1.2.9
Affected PluginBackup Migration
Affected Version<= 1.2.8
CVSS7.5High
CVEN/A
View all Backup Migration vulnerabilities

Vulnerability Overview

The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.8 via config and log files in the wp-content/backup-migration/ folder. This can allow unauthenticated attackers to extract sensitive data in certain configurations, including the site administrator's email address and the locations of site backups as well as the backups themselves.

Technical Analysis

REMEDIATION: Update to version 1.2.9, or a newer patched version --- IDENTIFIER: CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory) The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C