What the vulnerability does
01Description
Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.
Explanation of Vulnerability in Simple Terms
The WordPress Backup & Migration plugin through version 1.4.7 exposes sensitive information in backup files or logs. An attacker with network access can retrieve partial data without authentication, though significant effort is required. This affects confidentiality but not data integrity or availability. Update to a version newer than 1.4.7.
What an attacker can do
Read sensitive information from backup files or system logs without authentication.
Potential impact on your site
Backup files or logs may leak sensitive data to unauthenticated attackers, risking exposure of credentials or configuration details.
Conditions required to exploit
Network access to the site; high attack complexity suggests the vulnerability requires specific conditions or timing.
Key dates
External resources
Related vulnerabilities