CVE-2022-4932: Total Upkeep <= 1.14.13 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure
The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeatreceived() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions and above to retrieve back-up paths that can subsequently be used to download the back-up.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-4932.
What is the severity of CVE-2022-4932?
The severity of CVE-2022-4932 is medium (4.3).
What is the affected software of CVE-2022-4932?
The affected software of CVE-2022-4932 is the Total Upkeep plugin for WordPress version up to and including 1.14.13.
What is the vulnerability description of CVE-2022-4932?
CVE-2022-4932 is an information disclosure vulnerability in the Total Upkeep plugin for WordPress, allowing authenticated attackers to access sensitive information.
How can I fix CVE-2022-4932?
To fix CVE-2022-4932, update the Total Upkeep plugin for WordPress to a version later than 1.14.13.