Description
WordPress Plugin Backup Migration is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Backup Migration version 1.2.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.9 or latest
References
https://www.exploit-db.com/exploits/51445
https://plugins.svn.wordpress.org/backup-backup/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Relevanssi-A Better Search 'Seach Query' Field HTML Injection (2.7.2)
WebLogic Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2022-23437)
Oracle Database Server CVE-2009-1973 Vulnerability (CVE-2009-1973)
WordPress 4.1.x Multiple Vulnerabilities (4.1 - 4.1.30)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-6455)