Vulnerability details
Advisory: SB2022091201 - Arbitrary file read in BackupBuddy WordPress plugin
Vulnerable component: BackupBuddy
CVE-ID: CVE-2022-31474
CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C
CWE-ID: CWE-285 - Improper Authorization
Description:
The vulnerability allows a remote attacker to download arbitrary files from the server.
The vulnerability exists due to missing authorization for the feature responsible for remote downloading remote backups. A remote non-authenticated attacker can download arbitrary files from the server.
Note, the vulnerability is being actively exploited in the wild.
External links:
https://ithemes.com/blog/wordpress-vulnerability-report-special-edition-september-6-2022-backupbuddy/