CVE-2023-6750: Clone < 2.4.3 - Unauthenticated Backup Download
Published Jan 8, 2024
·Updated
The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.
Affected Software
1 affected component
BackupBliss Clone Wordpress<2.4.3
Event History
Jan 8, 2024
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-6750?
CVE-2023-6750 is considered a medium severity vulnerability due to the risk of unauthorized access to backup information.
2
How do I fix CVE-2023-6750?
To fix CVE-2023-6750, upgrade the Clone WordPress plugin to version 2.4.3 or later.
3
What is the impact of CVE-2023-6750?
The impact of CVE-2023-6750 includes potential exposure of sensitive backup data stored in publicly accessible files.
4
Who is affected by CVE-2023-6750?
CVE-2023-6750 affects users of the Clone WordPress plugin versions prior to 2.4.3.
5
How can I verify if my site is vulnerable to CVE-2023-6750?
You can verify if your site is vulnerable to CVE-2023-6750 by checking the version of the Clone WordPress plugin installed on your site.