PT-2025-16568 · WordPress · Wp Staging Pro
Haidv35
·
Published
2025-04-16
·
Updated
2025-04-16
·
CVE-2025-3104
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WP STAGING Pro WordPress Backup plugin versions up to and including 6.1.2
Description
The issue concerns the exposure of information due to missing capability checks in the
getOutdatedPluginsRequest() function. This allows unauthenticated attackers to reveal installed, active or inactive, outdated plugins.Recommendations
For WP STAGING Pro WordPress Backup plugin versions up to and including 6.1.2, update to a version later than 6.1.2 to resolve the issue.
As a temporary workaround, consider disabling the
getOutdatedPluginsRequest() function until a patch is available.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Staging Pro