BackWPup <= 3.4.1 - Unauthenticated Backup Download
2017-09-08 00:00
Larry W. CashdollarStrategic Overview
StatusPatched in 3.4.2
Affected PluginBackWPup – WordPress Backup & Restore Plugin
Affected Version
< 3.4.2CVSS7.5High
CVE
CVE-2017-2551Vulnerability Overview
Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.
Technical Analysis
REMEDIATION: Update to version 3.4.2, or a newer patched version --- IDENTIFIER: CWE-552 (Files or Directories Accessible to External Parties) The product makes files or directories accessible to unauthorized actors, even though they should not be.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C