CVE-2023-7164

The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.
Configurations

Configuration 1 (hide)

cpe:2.3:a:inpsyde:backwpup:*:*:*:*:*:wordpress:*:*

History

11 Apr 2025, 12:53

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Inpsyde
Inpsyde backwpup
References () https://wpscan.com/vulnerability/79b07f37-2c6b-4846-bb28-91a1e5bf112e/ - () https://wpscan.com/vulnerability/79b07f37-2c6b-4846-bb28-91a1e5bf112e/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:inpsyde:backwpup:*:*:*:*:*:wordpress:*:*

21 Nov 2024, 08:45

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/79b07f37-2c6b-4846-bb28-91a1e5bf112e/ - () https://wpscan.com/vulnerability/79b07f37-2c6b-4846-bb28-91a1e5bf112e/ -

30 Aug 2024, 10:15

Type Values Removed Values Added
Summary (en) The BackWPup WordPress plugin before 4.0.4 does not prevent visitors from leaking key information about ongoing backups, allowing unauthenticated attackers to download backups of a site's database. (en) The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.

03 Jul 2024, 01:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) El complemento BackWPup de WordPress anterior a 4.0.4 no impide que los visitantes filtren información clave sobre las copias de seguridad en curso, lo que permite a atacantes no autenticados descargar copias de seguridad de la base de datos de un sitio.

08 Apr 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-08 18:15

Updated : 2025-04-11 12:53


NVD link : CVE-2023-7164

Mitre link : CVE-2023-7164

CVE.ORG link : CVE-2023-7164


JSON object : View

Products Affected

inpsyde

  • backwpup