PT-2023-32291 · WordPress · Wordpress Backup & Migration

Krzysztof Zając

·

Published

2023-11-27

·

Updated

2023-12-01

·

CVE-2023-5737

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress Backup & Migration WordPress plugin versions prior to 1.4.4
Description The issue allows users with a role as low as Subscriber to update some plugin settings due to a lack of authorization for certain AJAX requests.
Recommendations For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-5737

Affected Products

Wordpress Backup & Migration