The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/64ba4461-bbba-45eb-981f-bb5f2e5e56e1/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/64ba4461-bbba-45eb-981f-bb5f2e5e56e1/ | Exploit Third Party Advisory |
Configurations
History
08 May 2025, 16:53
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:everestthemes:everest_backup:*:*:*:*:*:wordpress:*:* | |
References | () https://wpscan.com/vulnerability/64ba4461-bbba-45eb-981f-bb5f2e5e56e1/ - Exploit, Third Party Advisory | |
First Time |
Everestthemes everest Backup
Everestthemes |
21 Nov 2024, 08:45
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/64ba4461-bbba-45eb-981f-bb5f2e5e56e1/ - |
09 Aug 2024, 20:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
15 Apr 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-15 05:15
Updated : 2025-05-08 16:53
NVD link : CVE-2023-7201
Mitre link : CVE-2023-7201
CVE.ORG link : CVE-2023-7201
JSON object : View
Products Affected
everestthemes
- everest_backup
CWE