CVE-2023-6113
HIGH 7.5EPSS 0.8%
The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not prevent visitors from leaking key information about ongoing backups processes, allowing unauthenticated attackers to download said backups later.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS
- 0.78% chance of exploitation in the next 30 days, 54th percentile
- Published
- 2024-01-01
- Updated
- 2025-06-18
Proof-of-concept exploits (2)
- https://research.cleantalk.org/cve-2023-6113-wp-staging-unauth-sensitive-data-exposure-to…
- https://wpscan.com/vulnerability/5a71049a-09a6-40ab-a4e8-44634869d4fb