PT-2024-15860 · WordPress · Backuply

·

CVE-2024-0842

·

Published

2024-02-08

·

Updated

2024-02-15

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress versions 1.2.5 and earlier
Description The issue is related to a Denial of Service vulnerability. This vulnerability is due to direct access of the backuply/restore ins.php file, which allows unauthenticated attackers to make excessive requests, resulting in the server running out of resources.
Recommendations For versions 1.2.5 and earlier, consider disabling direct access to the backuply/restore ins.php file as a temporary workaround until a patch is available. Restrict access to this file to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-0842

Affected Products

Backuply