Description
WordPress Plugin Backup Migration is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Backup Migration version 1.2.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.9 or latest
References
https://www.exploit-db.com/exploits/51445
https://plugins.svn.wordpress.org/backup-backup/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Xorbin Analog Flash Clock Cross-Site Scripting (1.0)
Lighttpd Resource Management Errors Vulnerability (CVE-2010-0295)
MySQL CVE-2019-2991 Vulnerability (CVE-2019-2991)
WordPress Plugin Timetable and Event Schedule by MotoPress Unspecified Vulnerability (2.4.3)
WordPress Plugin WOOCS-Currency Switcher for WooCommerce Professional Cross-Site Scripting (1.3.7.4)