BackWPup <= 3.4.1 - Unauthenticated Backup Download

2017-09-08 00:00
Larry W. Cashdollar

Strategic Overview

Status
Patched in 3.4.2
Affected Version< 3.4.2
CVSS7.5High
CVECVE-2017-2551
View all BackWPup – WordPress Backup & Restore Plugin vulnerabilities

Vulnerability Overview

Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.

Technical Analysis

REMEDIATION: Update to version 3.4.2, or a newer patched version --- IDENTIFIER: CWE-552 (Files or Directories Accessible to External Parties) The product makes files or directories accessible to unauthorized actors, even though they should not be.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C