QID 150771
Date Published: 2024-01-17
QID 150771: WordPress Backup Migration Plugin: Sensitive Data Exposure (CVE-2023-6271)
This WordPress migrator plugin lets you migrate your WordPress site between any hosts or domains.
The plugin stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.
Affected Versions:
WordPress The Backup Migration Plugin before 1.3.6.
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of this vulnerability could allow an unauthorized attacker to gain Sensitive Information.
Solution
Customers are advised to upgrade to The Backup Migration 1.3.6 or later version to remediate this vulnerability.
Vendor References
CVEs related to QID 150771
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Backup Migration |
|