First published: Tue Jun 27 2023(Updated: )
The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient controls on the storage of back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including the entire installations database if a backup occurs and the deletion of the back-up files fail.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
MainWP Child Reports | <=4.4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-3132.
The severity of CVE-2023-3132 is high with a severity value of 7.5.
Versions up to and including 4.4.1.1 of the MainWP Child plugin are affected.
The MainWP Child plugin is vulnerable to Sensitive Information Exposure due to insufficient controls on the storage of back-up files.
Unauthenticated attackers can exploit this vulnerability to extract sensitive data, including the entire installation, from the MainWP Child plugin.