CVE-2023-7164: BackWPup < 4.0.4 - Unauthenticated Backup Download
Published Apr 8, 2024
·Updated
The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.
Affected Software
1 affected component
BackWPup BackWPup<4.0.4
Event History
Apr 8, 2024
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-7164?
CVE-2023-7164 has a severity rating that indicates a high risk due to the potential exposure of sensitive database backups.
2
How do I fix CVE-2023-7164?
To fix CVE-2023-7164, update the BackWPup plugin to version 4.0.4 or later.
3
What are the potential consequences of CVE-2023-7164?
The potential consequences of CVE-2023-7164 include unauthorized access to site backups and exposure of sensitive data.
4
Who is affected by CVE-2023-7164?
CVE-2023-7164 affects users of the BackWPup WordPress plugin versions prior to 4.0.4.
5
Can CVE-2023-7164 be exploited remotely?
Yes, CVE-2023-7164 can be exploited remotely by unauthenticated attackers who can access the backup folder.