CVE-2024-12850
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Published Dec 24, 2024
CWE ID 22
Summary
CVE-2024-12850 is a vulnerability affecting the Database Backup and Check Tables Automated With Scheduler plugin for WordPress. This issue allows authenticated attackers, with administrator-level access and above, to traverse directories through the database_backup_ajax_download() function. As a result, they can read the contents of arbitrary files on the server, potentially exposing sensitive information. This vulnerability occurs in all versions up to and including 2.32, and plugin users are urged to update as soon as a patch is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Database Backup And Check Tables Automated With Scheduler 2024 Plugin
Affected Vendors
- WordPress