CVE-2018-19456: Infoleak
Published May 7, 2019
·Updated
The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive information from server folders and files, as demonstrated by download.sql.
Affected Software
2 affected components
Wplaunchpad Wpbackupplus Wordpress<=2018-11-22
openSUSE Leap=42.3
Event History
May 7, 2019
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19456?
CVE-2018-19456 has been classified as a medium severity vulnerability due to its potential for sensitive information disclosure.
2
How do I fix CVE-2018-19456?
To fix CVE-2018-19456, update the WP Backup+ plugin to a version released after November 22, 2018.
3
What kind of information can be disclosed due to CVE-2018-19456?
CVE-2018-19456 allows remote attackers to potentially access sensitive information stored in server folders and files.
4
Which versions of the WP Backup+ plugin are affected by CVE-2018-19456?
The versions of WP Backup+ plugin up to and including November 22, 2018, are affected by CVE-2018-19456.
5
Is the vulnerability CVE-2018-19456 specific to WordPress?
Yes, CVE-2018-19456 specifically affects the WP Backup+ plugin used in WordPress environments.