CVE-2024-13911
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2024-13911 is a vulnerability affecting the Database Backup and Check Tables Automated With Scheduler plugin for WordPress. This issue allows authenticated attackers with Administrator-level access to extract sensitive information, including full database credentials, through the /dashboard/backup.php file. The vulnerability exists in all versions up to and including 2.35, putting numerous WordPress sites at risk. This sensitivity exposure can lead to serious data breaches and unauthorized access to sensitive information. It is highly recommended that WordPress site owners using the affected plugin version upgrade to the latest available patch as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Database Backup And Check Tables Automated With Scheduler 2024 Plugin
Affected Vendors
- WordPress