PT-2024-15860 · WordPress · Backuply
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress versions 1.2.5 and earlier
Description
The issue is related to a Denial of Service vulnerability. This vulnerability is due to direct access of the
backuply/restore ins.php file, which allows unauthenticated attackers to make excessive requests, resulting in the server running out of resources.Recommendations
For versions 1.2.5 and earlier, consider disabling direct access to the
backuply/restore ins.php file as a temporary workaround until a patch is available. Restrict access to this file to minimize the risk of exploitation.Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Backuply