PT-2025-41630 · WordPress · Everest Backup+1
Carl Pearson
+1
·
Published
2025-10-11
·
Updated
2026-01-19
·
CVE-2025-11380
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin versions prior to 2.3.6
Description
The Everest Backup plugin for WordPress allows unauthorized access to data due to a missing capability check on the
everest process status AJAX action. This allows unauthenticated attackers to retrieve back-up file locations, which can then be accessed and downloaded. This requires a back-up to be running in order for an attacker to retrieve the back-up location.Recommendations
Update to version 2.3.6 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Everest Backup
Wordpress