Description
WordPress Plugin BackWPup is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently brute force backup files location. WordPress Plugin BackWPup version 3.4.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.4.2 or latest
References
Related Vulnerabilities
WordPress Plugin Export Users to CSV Unspecified Vulnerability (1.3)
Lighttpd Other Vulnerability (CVE-2007-3947)
OpenSSL Session Fixation Vulnerability (CVE-1999-0428)
WordPress Plugin Contact Form 7 Integrations Multiple Cross-Site Scripting Vulnerabilities (1.3.10)
Liferay Portal Deserialization of Untrusted Data Vulnerability (CVE-2020-7961)