WordPress Plugin Vulnerabilities

JetBackup < 1.4.0 - Arbitrary File Upload via CSRF

Description

The plugin does not have CSRF checks when importing backups, allowing attackers to make logged in admin to upload arbitrary files via a CSRF attack

Affects Plugins

Fixed in 1.4.0

References

Miscellaneous

Original Researcher
Chloe Chamberland
Verified
No

Timeline

Publicly Published
2020-07-16 (about 5 years ago)
Added
2023-03-07 (about 3 years ago)
Last Updated
2023-03-07 (about 3 years ago)

Other