First published: Tue May 07 2019(Updated: )
The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive information from server folders and files, as demonstrated by download.sql.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
wplaunchpad WPbackupplus WordPress | <=2018-11-22 | |
openSUSE | =42.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19456 has been classified as a medium severity vulnerability due to its potential for sensitive information disclosure.
To fix CVE-2018-19456, update the WP Backup+ plugin to a version released after November 22, 2018.
CVE-2018-19456 allows remote attackers to potentially access sensitive information stored in server folders and files.
The versions of WP Backup+ plugin up to and including November 22, 2018, are affected by CVE-2018-19456.
Yes, CVE-2018-19456 specifically affects the WP Backup+ plugin used in WordPress environments.