CVE-2023-5775: BackWPup <= 4.0.2 - Plaintext Storage of Backup Destination Password
The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. This makes it possible for authenticated attackers, with administrator-level access, to retrieve the password from the password input field in the UI or from the options table where the password is stored.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5775?
CVE-2023-5775 is considered a high severity vulnerability due to the risk of password theft.
How do I fix CVE-2023-5775?
To fix CVE-2023-5775, update the BackWPup plugin to a version higher than 4.0.2.
What versions of the BackWPup plugin are affected by CVE-2023-5775?
CVE-2023-5775 affects all versions of the BackWPup plugin up to and including version 4.0.2.
Who can exploit CVE-2023-5775?
Authenticated attackers with administrative access can exploit CVE-2023-5775 to access plaintext backup destination passwords.
What impact does CVE-2023-5775 have on WordPress sites?
CVE-2023-5775 allows attackers to gain unauthorized access to sensitive backup data, compromising the security of WordPress sites.