BackWPup <= 4.0.2 - Plaintext Storage of Backup Destination Password
Strategic Overview
- Status
- Patched in 4.0.3
- Affected Plugin
- BackWPup – WordPress Backup & Restore Plugin
- Affected Version
<= 4.0.2- CVSS
- 2.2Low
- Weakness type
- CWE-256 · Plaintext Storage of a Password
- CVE
CVE-2023-5775
At a glance
CVE-2023-5775 is a low-severity Plaintext Storage of a Password vulnerability in the BackWPup WordPress plugin, affecting versions <= 4.0.2. It carries a CVSS score of 2.2 (reachable over the network). The issue is fixed in version 4.0.3; sites on affected versions should update now. Disclosed February 2024, reported by Stefan Marjanov.
Vulnerability Overview
The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. This makes it possible for authenticated attackers, with administrator-level access, to retrieve the password from the password input field in the UI or from the options table where the password is stored.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, and no interaction from a victim user.
CWE-256: Plaintext Storage of a Password
The product stores a password in plaintext within resources such as memory or files.
Remediation
Update to version 4.0.3, or a newer patched version
How does WordSec protect against this?
The fix is the thing that ends this: BackWPup 4.0.3 closes this, and updating the plugin is the step that ends it.
- Alerts
External References
Related records
Other vulnerabilities in BackWPup – WordPress Backup & Restore Plugin
- 9.8CVE-2011-4342: BackWPup <= 1.7.1 Remote File Inclusion
CVE-2011-4342 - 8.7CVE-2023-5504: BackWPup <= 4.0.1 Directory Traversal
CVE-2023-5504 - 7.5CVE-2023-7164: BackWPup <= 4.0.3 Sensitive Information Exposure
CVE-2023-7164 - 7.5CVE-2017-2551: BackWPup <= 3.4.1 Backup Download
CVE-2017-2551 - 7.5CVE-2011-5208: BackWPup – WordPress Backup Plugin Directory Traversal
CVE-2011-5208 - 7.2CVE-2026-65443: BackWPup <= 5.7.4 Stored Cross-Site Scripting
CVE-2026-65443 - 7.2CVE-2026-6227: BackWPup <= 5.6.6 Local File Inclusion
CVE-2026-6227 - 7.2CVE-2025-15041: BackWPup 5.0.0 - 5.6.2 Privilege Escalation
CVE-2025-15041
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C