The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug logs. This makes it possible for unauthenticated attackers to retrieve the debug log which may contain information like system errors which could contain sensitive information.
History

Mon, 05 May 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Backupbolt
Backupbolt backup Bolt
CPEs cpe:2.3:a:backupbolt:backup_bolt:*:*:*:*:*:wordpress:*:*
Vendors & Products Backupbolt
Backupbolt backup Bolt

Wed, 04 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-03-18T19:05:53.302Z

Updated: 2024-12-04T14:59:43.541Z

Reserved: 2024-01-18T20:42:45.975Z

Link: CVE-2023-7236

cve-icon Vulnrichment

Updated: 2024-08-02T08:57:35.245Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-18T19:15:06.207

Modified: 2025-05-05T17:58:10.357

Link: CVE-2023-7236

cve-icon Redhat

No data.