What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.
Explanation of Vulnerability in Simple Terms
The WPBackItUp Backup and Restore plugin for WordPress versions up to 1.50 is vulnerable to cross-site request forgery (CSRF). An attacker can trick a logged-in site administrator into performing unwanted actions, such as modifying backup settings or triggering backup operations, by sending them a malicious link or embedding code on a webpage. The vulnerability requires the admin to click the link or visit the attacker's page while logged into WordPress.
What an attacker can do
Trick a logged-in admin into performing unwanted backup or plugin actions without their knowledge.
Potential impact on your site
An attacker could modify backup settings, delete backups, or trigger unintended backup operations on your site.
Conditions required to exploit
Admin must be logged into WordPress and click a malicious link or visit an attacker-controlled page.
Key dates
External resources
Related vulnerabilities