The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.
History

Fri, 11 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Inpsyde
Inpsyde backwpup
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:inpsyde:backwpup:*:*:*:*:*:wordpress:*:*
Vendors & Products Inpsyde
Inpsyde backwpup

Fri, 30 Aug 2024 09:30:00 +0000

Type Values Removed Values Added
Description The BackWPup WordPress plugin before 4.0.4 does not prevent visitors from leaking key information about ongoing backups, allowing unauthenticated attackers to download backups of a site's database. The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-04-08T17:28:14.247Z

Updated: 2024-08-30T09:09:47.349Z

Reserved: 2023-12-28T17:20:48.452Z

Link: CVE-2023-7164

cve-icon Vulnrichment

Updated: 2024-08-02T08:50:08.324Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-08T18:15:08.287

Modified: 2025-04-11T12:53:18.497

Link: CVE-2023-7164

cve-icon Redhat

No data.