// For flags

CVE-2022-1577

Database Backup for WordPress < 2.5.2 - Arbitrary Schedule Settings Update via CSRF

Severity Score

5.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. This could lead to cases where attackers can send backup notification emails to themselves, which contain more details. Or disable the automatic backup schedule

El plugin Database Backup para WordPress versiones anteriores a 2.5.2, no presenta una comprobación de tipo CSRF cuando es actualizada la configuración de las copias de seguridad programadas, lo que podría permitir a un atacante hacer que un administrador conectado las cambie por medio de un ataque de tipo CSRF. Esto podría conllevar casos en los que los atacantes puedan enviarse a sí mismos correos electrónicos de notificación de copias de seguridad, que contienen más detalles. O deshabilitar la programación de copias de seguridad automáticas

*Credits: Daniel Ruf
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-05-04 CVE Reserved
  • 2022-05-11 CVE Published
  • 2023-12-28 EPSS Updated
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Deliciousbrains
Search vendor "Deliciousbrains"
Database Backup
Search vendor "Deliciousbrains" for product "Database Backup"
< 2.5.2
Search vendor "Deliciousbrains" for product "Database Backup" and version " < 2.5.2"
wordpress
Affected