PT-2024-14919 · WordPress · Backup Migration
Rafshanzani Suhada
·
Published
2024-01-11
·
Updated
2025-12-18
·
CVE-2023-6266
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Backup Migration plugin for WordPress versions up to, and including, 1.3.6
Description
The issue arises from insufficient path and file validation on the
BMI BACKUP case of the handle downloading function. This allows unauthenticated attackers to download backup files, potentially exposing sensitive information such as user passwords, personally identifiable information (PII), database credentials, and more.Recommendations
For versions up to, and including, 1.3.6, update to a version higher than 1.3.6 to resolve the issue.
As a temporary workaround, consider restricting access to the
handle downloading function until a patch is available.Fix
Information Disclosure
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Backup Migration