PT-2024-38261 · WordPress · Migration

Dmitry Ignatyev

·

Published

2024-10-01

·

Updated

2024-10-07

·

CVE-2024-7315

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Migration, Backup, Staging WordPress plugin versions prior to 0.9.106
Description The issue concerns the insufficient randomness in filenames created during backup generation, which could be bruteforced by attackers to leak sensitive information about said backups.
Recommendations For versions prior to 0.9.106, update to version 0.9.106 or later to resolve the issue. As a temporary workaround, consider restricting access to backup files to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-7315

Affected Products

Migration