CVE-2020-36667: JetBackup – WP Backup, Migrate & Restore <= 1.4.1 - Missing Authorization to Unauthorized Backup Location Change
The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location changes in versions up to, and including 1.4.1 due to a lack of proper capability checking on the backupguardclouddropbox, backupguardcloudgdrive, and backupguardcloudoneDrive functions. This makes it possible for authenticated attackers, with minimal permissions, such as a subscriber to change to location of back-ups and potentially steal sensitive information from them.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-36667.
What is the title of this vulnerability?
The title of this vulnerability is 'The JetBackup – WP Backup Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location changes'.
What is the severity of CVE-2020-36667?
The severity of CVE-2020-36667 is medium (5.4).
What software versions are affected by CVE-2020-36667?
Versions up to, and including 1.4.1 of the JetBackup – WP Backup Migrate & Restore plugin for WordPress are affected by CVE-2020-36667.
What is the CWE number for CVE-2020-36667?
The CWE number for CVE-2020-36667 is 862.