The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Metrics
Affected Vendors & Products
References
History
Thu, 08 May 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Everestthemes
Everestthemes everest Backup |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:everestthemes:everest_backup:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Everestthemes
Everestthemes everest Backup |
Fri, 09 Aug 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-04-15T05:00:01.572Z
Updated: 2024-08-09T20:01:33.240Z
Reserved: 2024-01-02T22:54:43.113Z
Link: CVE-2023-7201

Updated: 2024-08-02T08:57:34.095Z

Status : Analyzed
Published: 2024-04-15T05:15:14.583
Modified: 2025-05-08T16:53:40.513
Link: CVE-2023-7201

No data.