CVE-2020-7241
HIGH 7.5EPSS 2.4%
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing random ID numbers, guessing date strings with a 2020_{0..1}{0..2}_{0..3}{0..9} format, guessing UNIX timestamps, and making HTTPS requests with the complete guessed URL.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 2.43% chance of exploitation in the next 30 days, 83th percentile
- Published
- 2020-01-20
- Updated
- 2024-08-04
Proof-of-concept exploits (1)
- V1n1v131r4/Exploiting-WP-Database-Backup-WordPress-Plugin4★ · 2020-02-06