WordPress Plugin Vulnerabilities

Total Upkeep by BoldGrid < 1.14.10 - Unauthenticated Backup Download

Description

The plugin does not restrict access to a file containing sensitive information, such as the internal path of backups, which may then allow unauthenticated users to download them.

Proof of Concept

Affects Plugins

Fixed in 1.14.10

References

Exploitdb

Classification

Type
ACCESS CONTROLS
CWE
CVSS

Miscellaneous

Original Researcher
Wadeek
Verified
Yes

Timeline

Publicly Published
2020-12-14 (about 5 years ago)
Added
2020-12-14 (about 5 years ago)
Last Updated
2020-12-15 (about 5 years ago)

Other