vendor:
Total Upkeep
by:
Wadeek
6.5
CVSS
MEDIUM
Database and Files Backup Download
200
CWE
Product Name: Total Upkeep
Affected Version From: 1.14.9
Affected Version To: 1.14.9
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: BackBox Linux
2020
WordPress Plugin Total Upkeep 1.14.9 – Database and Files Backup Download
An unauthenticated attacker can access the 'readme.txt' file to reveal the plugin version, 'env-info.php' file to reveal the server information and 'restore-info.json' file to reveal the name and location of the archive containing the backups without authentication.
Mitigation:
Ensure that the plugin is up-to-date and authentication is required to access the sensitive files.