Description
WordPress Plugin Backup and Restore WordPress-WPBackItUp is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Backup and Restore WordPress-WPBackItUp version 1.6.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.0 or latest
References
http://www.estacion-informatica.com/2014/05/wp-backitup-arbitrary-file-deletion.html
http://www.quantika14.com/blog/2014/04/28/wordpressa-rep-1-28-abril-2014/
Related Vulnerabilities
Liferay Portal Incorrect Authorization Vulnerability (CVE-2024-25149)
WordPress Plugin LIQUID SPEECH BALLOON Cross-Site Scripting (1.0.6)
MySQL CVE-2017-3635 Vulnerability (CVE-2017-3635)
Internet Information Services Other Vulnerability (CVE-2001-0333)
Tornado URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-28370)