CVE-2023-7201: Everest Backup < 2.2.5 - Admin+ Arbitrary File Upload
The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7201?
CVE-2023-7201 is considered a high severity vulnerability due to the potential for arbitrary file uploads by high privilege users.
How do I fix CVE-2023-7201?
To fix CVE-2023-7201, update the Everest Backup plugin to version 2.2.5 or later.
Who is affected by CVE-2023-7201?
CVE-2023-7201 affects users of the Everest Backup WordPress plugin prior to version 2.2.5.
What type of exploit is associated with CVE-2023-7201?
CVE-2023-7201 allows high privilege users to upload arbitrary files on the server, which can lead to serious security risks.
Can CVE-2023-7201 be exploited in a multisite setup?
Yes, CVE-2023-7201 can be exploited in a multisite setup, allowing unauthorized file uploads.