CVE-2024-0761
The File Manager plugin for WordPress through version 7.2.1 allows unauthenticated attackers to access sensitive data and site backups because backup filenames are generated with insufficient randomness, relying only on a timestamp combined with four random digits. When the .htaccess file fails to restrict access to the backup directory, attackers can predict and retrieve these backup files. This vulnerability exposes sensitive information that should remain protected from unauthorized access.
Based on public CVE data (MITRE/NVD).