CVE-2024-12330

The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.3 via publicly accessible back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including all information stored in the database.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) El complemento WP Database Backup – Unlimited Database y Files Backup de Backup para WP para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 7.3 incluida a través de archivos de respaldo de acceso público. Esto permite que atacantes no autenticados extraigan datos confidenciales, incluida toda la información almacenada en la base de datos.

09 Jan 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-09 11:15

Updated : 2026-04-15 00:35


NVD link : CVE-2024-12330

Mitre link : CVE-2024-12330

CVE.ORG link : CVE-2024-12330


JSON object : View

Products Affected

No product.

CWE
CWE-530

Exposure of Backup File to an Unauthorized Control Sphere