The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug logs. This makes it possible for unauthenticated attackers to retrieve the debug log which may contain information like system errors which could contain sensitive information.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/2a4557e2-b764-4678-a6d6-af39dd1ba76b/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/2a4557e2-b764-4678-a6d6-af39dd1ba76b/ | Exploit Third Party Advisory |
Configurations
History
05 May 2025, 17:58
Type | Values Removed | Values Added |
---|---|---|
First Time |
Backupbolt
Backupbolt backup Bolt |
|
References | () https://wpscan.com/vulnerability/2a4557e2-b764-4678-a6d6-af39dd1ba76b/ - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:backupbolt:backup_bolt:*:*:*:*:*:wordpress:*:* |
04 Dec 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.7 |
CWE | CWE-79 |
21 Nov 2024, 08:45
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://wpscan.com/vulnerability/2a4557e2-b764-4678-a6d6-af39dd1ba76b/ - |
18 Mar 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-18 19:15
Updated : 2025-05-05 17:58
NVD link : CVE-2023-7236
Mitre link : CVE-2023-7236
CVE.ORG link : CVE-2023-7236
JSON object : View
Products Affected
backupbolt
- backup_bolt
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')