WP Staging Pro <= 6.1.2 - Unauthenticated Information Exposure via getOutdatedPluginsRequest Function
2025-04-15 19:52
haidv35Strategic Overview
StatusPatched in 6.1.3
Affected PluginWP STAGING Pro WordPress Backup Plugin
Affected Version
<= 6.1.2CVSS5.3Medium
CVE
CVE-2025-3104Vulnerability Overview
The WP STAGING Pro WordPress Backup Plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 6.1.2 due to missing capability checks on the getOutdatedPluginsRequest() function. This makes it possible for unauthenticated attackers to reveal outdated installed active or inactive plugins.
Technical Analysis
REMEDIATION: Update to version 6.1.3, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C