CVE-2025-24651
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Published Apr 17, 2025
CWE ID 532
Summary
CVE-2025-24651 is a log file vulnerability affecting the WebToffee WordPress Backup & Migration plugin. An attacker can exploit this issue by inserting sensitive information into the log file, making it possible for unauthorized parties to retrieve embedded sensitive data. This vulnerability impacts versions of the plugin from n/a through 1.5.3, and users are advised to update to the latest version to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.