CVE-2023-5737

CVE-2023-5737: WordPress Backup & Migration < 1.4.4 - Subscriber+ Plugin Settings Update

Vendor Unknown
Product WordPress Backup & Migration
Published November 27, 2023
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.

Key dates

02Disclosure timeline

November 27, 2023 CVE published
August 2, 2024 Record updated