PT-2024-15217 · WordPress · Backwpup

Dmitry Ignatyev

·

Published

2024-03-18

·

Updated

2025-12-19

·

CVE-2023-7164

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions BackWPup WordPress plugin versions prior to 4.0.4
Description The issue allows unauthenticated attackers to download backups of a site's database due to the lack of prevention of Directory Listing in the temporary backup folder. This exposes sensitive data, potentially leading to account hijacking and system compromise. Over 600,000 WordPress sites using the BackWPup plugin are estimated to be at risk.
Recommendations For versions prior to 4.0.4, update to version 4.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the temporary backup folder to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2023-7164

Affected Products

Backwpup