CVE-2023-7164

The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.
Configurations

Configuration 1 (hide)

cpe:2.3:a:inpsyde:backwpup:*:*:*:*:*:wordpress:*:*

History

11 Apr 2025, 12:53

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/79b07f37-2c6b-4846-bb28-91a1e5bf112e/ - () https://wpscan.com/vulnerability/79b07f37-2c6b-4846-bb28-91a1e5bf112e/ - Exploit, Third Party Advisory
CWE NVD-CWE-noinfo
First Time Inpsyde backwpup
Inpsyde
CPE cpe:2.3:a:inpsyde:backwpup:*:*:*:*:*:wordpress:*:*

21 Nov 2024, 08:45

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/79b07f37-2c6b-4846-bb28-91a1e5bf112e/ - () https://wpscan.com/vulnerability/79b07f37-2c6b-4846-bb28-91a1e5bf112e/ -

30 Aug 2024, 10:15

Type Values Removed Values Added
Summary (en) The BackWPup WordPress plugin before 4.0.4 does not prevent visitors from leaking key information about ongoing backups, allowing unauthenticated attackers to download backups of a site's database. (en) The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.

03 Jul 2024, 01:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

08 Apr 2024, 18:48

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-08 18:15

Updated : 2025-04-11 12:53


NVD link : CVE-2023-7164

Mitre link : CVE-2023-7164

CVE.ORG link : CVE-2023-7164


JSON object : View

Products Affected

inpsyde

  • backwpup