CVE-2024-13911

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Mar 1, 2025
CWE ID 200

Summary

CVE-2024-13911 is a vulnerability affecting the Database Backup and Check Tables Automated With Scheduler plugin for WordPress. This issue allows authenticated attackers with Administrator-level access to extract sensitive information, including full database credentials, through the /dashboard/backup.php file. The vulnerability exists in all versions up to and including 2.35, putting numerous WordPress sites at risk. This sensitivity exposure can lead to serious data breaches and unauthorized access to sensitive information. It is highly recommended that WordPress site owners using the affected plugin version upgrade to the latest available patch as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Database Backup And Check Tables Automated With Scheduler 2024 Plugin

Affected Vendors

  • WordPress