Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin, f8d02775428e8ca895e9b0fe1b5f57146e965e68
- CVE, Research URL
- Home page URL
- Published on
- -
- Research Description
- Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin [everest-backup] < 1.0.8 Everest Backup <= 1.0.7 - Missing Authorization Checks on Backup Exports The Everest Backup plugin for WordPress is vulnerable to backup export disclosure in versions up to, and including, 1.0.7. This is due to insufficient access controls on the everest_backup_get_ajax_response() function. This makes it possible for authenticated attackers to reveal sensitive information about back-ups created by the plugin.
- Affected versions
-
max 1.0.8.
- Status
-
vulnerable