CVE-2023-5775
Last modified
CVE-2023-5775 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. This makes it possible for authenticated attackers, with administrator-level access, to retrieve the password from the password input field in the UI or from the options table where the password is stored.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Inpsyde | Backwpup | < 4.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-5775?
How severe is CVE-2023-5775?
How do I fix CVE-2023-5775?
Are you affected by CVE-2023-5775?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
