CVE-2024-13910

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Mar 1, 2025
CWE ID 22

Summary

CVE-2024-13910 is a vulnerability affecting the Database Backup and Check Tables Automated With Scheduler plugin for WordPress. This issue allows authenticated attackers with Administrator-level access to delete arbitrary files on the server due to insufficient file path validation in the 'database_backup_ajax_delete' function. This vulnerability, present in all versions up to 2.35, poses a significant risk as the deletion of certain files, such as wp-config.php, can lead to remote code execution. The vulnerability was partially patched in version 2.36.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Database Backup And Check Tables Automated With Scheduler 2024 Plugin

Affected Vendors

  • WordPress