CVE-2020-7241
WP Database Backup <= 5.5 - Unauthenticated Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing random ID numbers, guessing date strings with a 2020_{0..1}{0..2}_{0..3}{0..9} format, guessing UNIX timestamps, and making HTTPS requests with the complete guessed URL.
El plugin WP Database Backup versiones hasta 5.5 para WordPress, por defecto almacena descargas localmente en el directorio wp-content/uploads/db-backup/. Esto podría permitir a atacantes leer archivos ZIP al adivinar los números de ID aleatorios, adivinando cadenas de fecha con un formato 2020_{0..1}{0..2}_{0..3}{0..9}, adivinando las marcas de tiempo UNIX y realizar peticiones HTTPS con la URL adivinada completa.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-20 CVE Reserved
- 2020-01-20 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2025-01-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-330: Use of Insufficiently Random Values
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins/wp-database-backup/#developers | Third Party Advisory | |
https://zeroauth.ltd/blog/2020/01/21/analysis-on-cve-2020-7241-misrepresenting-a-security-vulnerability | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/V1n1v131r4/Exploiting-WP-Database-Backup-WordPress-Plugin/blob/master/README.md | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpseeds Search vendor "Wpseeds" | Wp Database Backup Search vendor "Wpseeds" for product "Wp Database Backup" | <= 5.5 Search vendor "Wpseeds" for product "Wp Database Backup" and version " <= 5.5" | wordpress |
Affected
|