CVE-2024-31254: WordPress WordPress Backup & Migration plugin <= 1.4.7 - Sensitive Data Exposure via Log File vulnerability
Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31254?
CVE-2024-31254 is a medium severity vulnerability that involves the exposure of sensitive information due to improper logging practices.
How do I fix CVE-2024-31254?
To fix CVE-2024-31254, update the WebToffee WordPress Backup & Migration plugin to the latest version beyond 1.4.7.
What software is affected by CVE-2024-31254?
CVE-2024-31254 affects the WebToffee WordPress Backup & Migration plugin versions up to and including 1.4.7.
What types of sensitive information are exposed in CVE-2024-31254?
CVE-2024-31254 can result in sensitive user data being written to log files, potentially accessible by unauthorized users.
When was CVE-2024-31254 disclosed?
CVE-2024-31254 was disclosed in 2024, impacting users of the affected WordPress plugin shortly thereafter.