CVE-2023-7204

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 29, 2024
Updated: Feb 5, 2024
CWE ID 668

Summary

CVE-2023-7204 is a vulnerability affecting the WP STAGING WordPress Backup plugin before version 3.2.0. This issue grants unauthorized access to cache files during the cloning process, potentially exposing sensitive data to attackers. An attacker could exploit this vulnerability to gain insight into a website's configuration or even steal sensitive information, such as login credentials or database details. The cloning process, intended to create a backup of a website for development or testing purposes, inadvertently provides an avenue for potential data breaches. To mitigate this risk, users should ensure their WP STAGING plugin is updated to the latest version, which addresses this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share