What the vulnerability does
01Description
Missing Authorization vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through <= 2.3.3.
Explanation of Vulnerability in Simple Terms
02Summary
WP SuperBackup versions 2.3.3 and earlier lack proper authorization checks, allowing authenticated users with low privileges to access backup functionality and modify site data beyond their intended permissions. The vulnerability affects confidentiality, integrity, and availability. An attacker needs a valid WordPress account to exploit it.
What an attacker can do
03Attacker Capabilities
Access and modify backup data and site content beyond their assigned role permissions.
Potential impact on your site
04Site Impact
Unauthorized users can read, modify, or delete backups and potentially access sensitive site data.
Conditions required to exploit
05Prerequisites
Attacker must have a valid low-privilege WordPress account (e.g., subscriber or contributor).
Key dates
06Disclosure timeline
December 31, 2024
CVE published
April 28, 2026
Record updated