PT-2021-15718 · WordPress · Vm Backups
0Xb9
·
Published
2021-04-05
·
Updated
2021-04-09
·
CVE-2021-24172
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
VM Backups WordPress plugin versions 1.0 and earlier
Description:
The issue allows attackers to make a logged-in user perform unwanted actions, such as generating backups of the database, plugins, and current data, due to the lack of CSRF checks.
Recommendations:
For VM Backups WordPress plugin versions 1.0 and earlier, consider disabling the plugin until a patch is available to prevent exploitation.
As a temporary workaround, restrict access to the plugin's functionality to minimize the risk of unwanted actions being performed by attackers.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm Backups