CVE-2020-37246 MEDIUM

CVE-2020-37246: WordPress Plugin Supsystic Backup 2.3.9 Local File Inclusion

Vendor Supsystic
Product Backup
Weakness CWE-98 · PHP file inclusion
Published May 16, 2026
Last update May 18, 2026

CVSS base score

6.9/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

Description

Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access sensitive files like /etc/passwd or delete files via the removeAction parameter.

Key dates

Disclosure timeline

May 16, 2026 CVE published
May 18, 2026 Record updated