cleantalk
Vulnerabilities and Security Researches

Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin, f8d02775428e8ca895e9b0fe1b5f57146e965e68

Published on
-
Research Description
Everest Backup &#8211; WordPress Cloud Backup, Migration, Restore &amp; Cloning Plugin [everest-backup] < 1.0.8 Everest Backup &lt;= 1.0.7 - Missing Authorization Checks on Backup Exports The Everest Backup plugin for WordPress is vulnerable to backup export disclosure in versions up to, and including, 1.0.7. This is due to insufficient access controls on the everest_backup_get_ajax_response() function. This makes it possible for authenticated attackers to reveal sensitive information about back-ups created by the plugin.
Affected versions
max 1.0.8.
Status
vulnerable