Show filters
977 Total Results
Displaying 91-100 of 977
Sort by:
Attacker Value
Unknown
CVE-2023-5505
Disclosure Date: August 17, 2024 (last updated August 17, 2024)
The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the job-specific backup folder. This allows authenticated attackers to store backups in arbitrary folders on the server provided they can be written to by the server. Additionally, default settings will place an index.php and a .htaccess file into the chosen directory (unless already present) when the first backup job is run that are intended to prevent directory listing and file access. This means that an attacker could set the backup directory to the root of another site in a shared environment and thus disable that site.
0
Attacker Value
Unknown
CVE-2024-38770
Disclosure Date: August 01, 2024 (last updated August 02, 2024)
Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication Bypass.This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.20.
0
Attacker Value
Unknown
CVE-2024-6559
Disclosure Date: July 16, 2024 (last updated July 16, 2024)
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.7.3. This is due the plugin utilizing sabre without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
0
Attacker Value
Unknown
CVE-2024-6210
Disclosure Date: July 11, 2024 (last updated January 05, 2025)
The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use.
0
Attacker Value
Unknown
CVE-2023-52183
Disclosure Date: June 11, 2024 (last updated June 12, 2024)
Missing Authorization vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.3.
0
Attacker Value
Unknown
CVE-2024-35664
Disclosure Date: June 04, 2024 (last updated June 06, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPvivid Team WPvivid Backup for MainWP allows Reflected XSS.This issue affects WPvivid Backup for MainWP: from n/a through 0.9.32.
0
Attacker Value
Unknown
CVE-2024-4469
Disclosure Date: May 31, 2024 (last updated May 31, 2024)
The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.
0
Attacker Value
Unknown
CVE-2024-3412
Disclosure Date: May 29, 2024 (last updated January 05, 2025)
The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpstg_processing AJAX action in all versions up to, and including, 3.4.3. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2024-29852
Disclosure Date: May 22, 2024 (last updated May 23, 2024)
Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.
0
Attacker Value
Unknown
CVE-2024-29851
Disclosure Date: May 22, 2024 (last updated May 23, 2024)
Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.
0