Description
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the process_status_unlink() function in all versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to delete the back-up progress files and cause a back-up to fail while it is in progress.
Problem types
Product status
* (semver)
Timeline
| 2025-09-18: | Vendor Notified |
| 2025-12-02: | Disclosed |
Credits
Jonas Benjamin Friedli
References
www.wordfence.com/...-7dc0-47a5-a203-6df4dfa0158b?source=cve
plugins.trac.wordpress.org/...t-backup&sfp_email=&sfph_mail=