CVE-2024-12850

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Dec 24, 2024
CWE ID 22

Summary

CVE-2024-12850 is a vulnerability affecting the Database Backup and Check Tables Automated With Scheduler plugin for WordPress. This issue allows authenticated attackers, with administrator-level access and above, to traverse directories through the database_backup_ajax_download() function. As a result, they can read the contents of arbitrary files on the server, potentially exposing sensitive information. This vulnerability occurs in all versions up to and including 2.32, and plugin users are urged to update as soon as a patch is available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Database Backup And Check Tables Automated With Scheduler 2024 Plugin

Affected Vendors

  • WordPress