CVE Database /
CVE-2022-4931
CVE · Medium
CVE-2022-4931 — BackUpWordPress [backupwordpress] < 3.13 (closed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-4931
|
BackUpWordPress [backupwordpress] < 3.13 (closed) |
Missing Authorization |
Medium
4.3
|
< 3.13
|
3.13 |
2022-02-23 |
—
|
CVE-2022-4931
The BackupWordPress plugin versions up to 3.12 contains an information disclosure vulnerability where the heartbeat_received() function lacks proper authorization checks. This flaw allows authenticated users with subscriber-level access or higher to discover backup file paths through WordPress heartbeat requests, enabling them to subsequently download these backup files.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings