CVE-2020-36668
EUVD-2020-2411007.03.2023, 14:15
The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and including, 1.4.0 due to a lack of proper capability checking on the backup_guard_get_manual_modal function called via an AJAX action. This makes it possible for subscriber-level attackers, and above, to invoke the function and obtain database table information.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jetbackup | jetbackup | 𝑥 ≤ 1.4.0 |
𝑥
= Vulnerable software versions
References