CVE-2024-7315

Published Oct 2, 2024

Last updated 10 months ago

Overview

Description
The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups.
Source
contact@wpscan.com
NVD status
Analyzed
Products
migration\,_backup\,_staging

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-338

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.