Updraft Plus <= 1.22.24 - Information Disclosure via updraft_ajaxrestore
2023-03-08 00:00
AnonymousStrategic Overview
StatusPatched in 1.23.1
Affected PluginUpdraftPlus: WP Backup & Migration Plugin
Affected Version
<= 1.22.24CVSS5.3Medium
CVE
N/AVulnerability Overview
The Updraft Plus plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 1.22.24. This is due to the fact that the 'updraft_ajaxrestore' function generates a log file containing system configuration information. This makes it possible for unauthenticated attackers to trigger generation of such a log file, though it is only possible to access it on configurations that do not respect the "deny from all" directive.
Technical Analysis
REMEDIATION: Update to version 1.23.1, or a newer patched version --- IDENTIFIER: CWE-532 (Insertion of Sensitive Information into Log File) The product writes sensitive information to a log file.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C