CVE-2023-45636: WordPress Backup & Migration plugin <= 1.4.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Backup & Migration: from n/a through <= 1.4.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45636?
CVE-2023-45636 is classified as a Missing Authorization vulnerability that can lead to unauthorized access.
How do I fix CVE-2023-45636?
To fix CVE-2023-45636, update your WebToffee WordPress Backup & Migration plugin to a version beyond 1.4.1.
Which versions of WebToffee WordPress Backup & Migration are affected by CVE-2023-45636?
CVE-2023-45636 affects all versions of WebToffee WordPress Backup & Migration up to and including version 1.4.1.
What types of attacks can be executed due to CVE-2023-45636?
CVE-2023-45636 can enable attackers to exploit incorrectly configured access control security levels, potentially leading to data exposure.
Is CVE-2023-45636 applicable to other WebToffee products?
CVE-2023-45636 specifically affects the WebToffee WordPress Backup & Migration plugin and is not known to impact other WebToffee products.