Skip to main content

Vendor/product archive

inpsyde / backwpup CVEs

Beta · best-effort

5 CVEs tagged to inpsyde / backwpup0 Critical, 3 High, 1 Medium, 1 Low, 0 Unrated.

CVE-2023-5505

Published Aug 17, 2024

The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the job-specific backup folder. This allows authenticated attack…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-7164

Published Apr 8, 2024

The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's da…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5775

Published Feb 26, 2024

The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin impro…

CVSS 2.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-5504

Published Jan 11, 2024

The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the Log File Folder. This allows authenticated attackers to stor…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-2551

Published Sep 28, 2017

Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1