vendor:
WordPress Plugin Database Backups
by:
0xB9
8.1
CVSS
HIGH
CSRF
Unknown
CWE
Product Name: WordPress Plugin Database Backups
Affected Version From: 1.2.2.6
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE: CVE-2021-24174
CPE: Unknown
Platforms Tested: Windows 10
2021
WordPress Plugin Database Backups 1.2.2.6 – ‘Database Backup Download’ CSRF
This plugin allows admins to create and download database backups. A CSRF can create DB backups stored publicly in the uploads directory.
Mitigation:
Unknown