WordPress Plugin Vulnerabilities
JetBackup < 1.4.0 - Arbitrary File Upload via CSRF
Description
The plugin does not have CSRF checks when importing backups, allowing attackers to make logged in admin to upload arbitrary files via a CSRF attack
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Chloe Chamberland
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-07-16 (about 5 years ago)
Added
2023-03-07 (about 3 years ago)
Last Updated
2023-03-07 (about 3 years ago)