HomeDefault status
unaffected
Any version before 2.0.0
affected
Description
The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication.
Problem types
Product status
Any version before 2.0.0
Credits
ymmfty0
WPScan
References
wpscan.com/...rability/e61293d0-2e1b-4dac-96c5-97fa17e38b16/