The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions and above to retrieve back-up paths that can subsequently be used to download the back-up.
2023-03-07T15:15:10.980
2024-11-21T07:36:16.787
Modified
CVSSv3.1: 4.3 (MEDIUM)
-
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | boldgrid | total_upkeep | ≤ 1.14.13 | Yes |