What the vulnerability does
01Description
Access Control vulnerability in WPBackItUp Backup and Restore WordPress allows . This issue affects Backup and Restore WordPress: from n/a through 1.50.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Access Control vulnerability in WPBackItUp Backup and Restore WordPress allows . This issue affects Backup and Restore WordPress: from n/a through 1.50.
Explanation of Vulnerability in Simple Terms
The WPBackItUp Backup and Restore plugin for WordPress does not properly check user permissions before allowing access to backup and restore functions. A logged-in user with low privileges can read or modify backups without authorization. This affects versions up to 1.50. Update to a version newer than 1.50 to resolve the issue.
What an attacker can do
A low-privilege user can read or modify site backups without proper authorization.
Potential impact on your site
Unauthorized users can access, download, or restore backups, risking data exposure or site integrity.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities