QID 150569
Date Published: 2022-09-14
QID 150569: WordPress Database Backup Plugin: Stored Cross-Site Scripting Vulnerability (CVE-2022-2271)
WP Database Backup plugin helps you to create Database Backup and Restore Database Backup easily on single click. manual or automated backups.
The plugin does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed.
Affected versions:
WP Database Backup WordPress plugin before 5.9
QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a plugin running on the target application.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive browser-based information.
Solution
Customers are advised to upgrade to WP Database Backup plugin 5.9 or later version to remediate this vulnerability. For more information regarding this vulnerability please refer WPScan Advisory.
Vendor References
CVEs related to QID 150569
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WPScan |
|