CVE-2025-62946: WordPress Everest Backup plugin <= 2.3.8 - Broken Access Control vulnerability
Missing Authorization vulnerability in everestthemes Everest Backup everest-backup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Everest Backup: from n/a through <= 2.3.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62946?
CVE-2025-62946 has been classified as a high severity vulnerability due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2025-62946?
To fix CVE-2025-62946, update Everest Backup to version 2.3.9 or later to ensure access control configurations are correctly implemented.
Who is affected by CVE-2025-62946?
CVE-2025-62946 affects users of Everest Backup plugin versions from any version to 2.3.8 on WordPress.
What type of vulnerability is CVE-2025-62946?
CVE-2025-62946 is a missing authorization vulnerability that can lead to inadequate access control.
What can be compromised due to CVE-2025-62946?
Due to CVE-2025-62946, attackers may exploit the vulnerability to gain unauthorized access to backups and sensitive data.