What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup.This issue affects WP SuperBackup: from n/a through <= 2.3.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup.This issue affects WP SuperBackup: from n/a through <= 2.3.3.
Explanation of Vulnerability in Simple Terms
WP SuperBackup versions 2.3.3 and earlier contain a deserialization vulnerability that allows authenticated attackers to execute arbitrary code on the site. The vulnerability requires an attacker to have low-level access and involves sending specially crafted data that the plugin processes without proper validation. Sites running affected versions should update immediately.
What an attacker can do
Run their own code on the site with the privileges of the WordPress user account.
Potential impact on your site
An attacker with basic site access can take full control of your WordPress installation and its data.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities