CVE-2013-2743: High severity backupbuddy vulnerability
Published Apr 2, 2013
·Updated
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via a crafted integer in the step parameter.
Affected Software
6 affected components
iThemes Backupbuddy=1.3.4
iThemes Backupbuddy=2.1.4
iThemes Backupbuddy=2.2.4
iThemes Backupbuddy=2.2.25
iThemes Backupbuddy=2.2.28
WordPress WordPress
Event History
Apr 2, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2743?
CVE-2013-2743 has been classified with a medium severity rating due to its potential for authentication bypass.
2
How do I fix CVE-2013-2743?
To fix CVE-2013-2743, update the BackupBuddy plugin to a version that has patched the vulnerability.
3
Which versions of BackupBuddy are affected by CVE-2013-2743?
CVE-2013-2743 affects BackupBuddy versions 1.3.4, 2.1.4, 2.2.4, 2.2.25, and 2.2.28.
4
Can CVE-2013-2743 be exploited remotely?
Yes, CVE-2013-2743 can be exploited by remote attackers to bypass authentication.
5
Is WordPress itself vulnerable to CVE-2013-2743?
No, WordPress itself is not vulnerable to CVE-2013-2743; the vulnerability exists specifically within certain versions of the BackupBuddy plugin.