CVE · Low

CVE-2024-3034 — BackUpWordPress [backupwordpress] < 3.14 (closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3034 BackUpWordPress [backupwordpress] < 3.14 (closed) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Low 2.7 < 3.14 3.14 2024-04-26

CVE-2024-3034

The BackUpWordPress plugin through version 3.13 contains a directory traversal vulnerability in the hmbkp_directory_browse parameter that allows authenticated administrators to access files and directories outside the intended scope. An attacker with administrator-level permissions or higher could exploit this flaw to navigate the server's filesystem beyond the plugin's restricted boundaries. The vulnerability was patched in version 3.14.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.