CVE-2015-10134: Simple Backup <= 2.7.10 - Arbitrary File Download via Path Traversal
The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the downloadbackupfile function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-config.php file from the affected site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-10134?
CVE-2015-10134 is considered a high severity vulnerability due to its potential to allow unauthorized file downloads.
How do I fix CVE-2015-10134?
To fix CVE-2015-10134, update the Simple Backup plugin to version 2.7.11 or later to ensure proper capability checks and file type validation.
What types of attacks can CVE-2015-10134 enable?
CVE-2015-10134 can enable attackers to exploit arbitrary file download vulnerabilities, potentially leading to sensitive information disclosure.
Which versions of Simple Backup are affected by CVE-2015-10134?
CVE-2015-10134 affects all versions of Simple Backup up to and including 2.7.10.
Is there any public exploit available for CVE-2015-10134?
Yes, there are public exploit examples available that demonstrate the arbitrary file download vulnerability in CVE-2015-10134.