WP Database Backup <= 5.1.2 - Unauthenticated Settings Update to Remote Code Execution
2019-03-24 00:00
AnonymousStrategic Overview
StatusPatched in 5.1.3
Affected Version
<= 5.1.2CVSS9.8Critical
CVE
N/AVulnerability Overview
The WP Database Backup plugin for WordPress is vulnerable to unauthenticated settings update that can lead to remote code execution via the wpsetting functionality in versions up to, and including, 5.1.2. This makes it possible for unauthenticated attackers to inject malicious code into settings that will execute when a back-up is triggered by an unsuspecting user.
Technical Analysis
REMEDIATION: Update to version 5.1.3, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C