CVE-2024-13910
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Mar 1, 2025
CWE ID 22
Summary
CVE-2024-13910 is a vulnerability affecting the Database Backup and Check Tables Automated With Scheduler plugin for WordPress. This issue allows authenticated attackers with Administrator-level access to delete arbitrary files on the server due to insufficient file path validation in the 'database_backup_ajax_delete' function. This vulnerability, present in all versions up to 2.35, poses a significant risk as the deletion of certain files, such as wp-config.php, can lead to remote code execution. The vulnerability was partially patched in version 2.36.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Database Backup And Check Tables Automated With Scheduler 2024 Plugin
Affected Vendors
- WordPress