vendor:
Backup
by:
Stephan Knauss
7,5
CVSS
HIGH
Exposure of sensitive information
200
CWE
Product Name: Backup
Affected Version From: 2.0.1
Affected Version To: 2.0.1
Patch Exists: NO
Related CWE: N/A
CPE: a:wordpress:backup
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
WordPress Backup plugin exposes site data
The default configuration of the WordPress Backup plugin exposes a logfile with filenames of the actual backups. The backup files are available for download once the name is extracted from this logfile. Depending on the settings this gives access to a copy of the WordPress database, wp-content, uploads, plugins or complete site.
Mitigation:
Local folder path setting should be set to a value that can not be guessed by default.