CVE-2023-5737: WordPress Backup & Migration < 1.4.4 - Subscriber+ Plugin Settings Update
The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of the WordPress Backup & Migration plugin?
The vulnerability ID of the WordPress Backup & Migration plugin is CVE-2023-5737.
What is the severity rating of CVE-2023-5737?
The severity rating of CVE-2023-5737 is medium with a score of 4.3.
What is the affected software of CVE-2023-5737?
The affected software of CVE-2023-5737 is the WordPress Backup & Migration plugin version up to 1.4.4.
What is the description of CVE-2023-5737?
CVE-2023-5737 is a vulnerability in the WordPress Backup & Migration plugin before version 1.4.4 that allows unauthorized AJAX requests, enabling users with low roles like Subscriber to update plugin settings.
Where can I find more information about CVE-2023-5737?
More information about CVE-2023-5737 can be found at the following reference: https://wpscan.com/vulnerability/c761c67c-eab8-4e1b-a332-c9a45e22bb13.