CVE Database /
CVE-2024-3034
CVE · Low
CVE-2024-3034 — BackUpWordPress [backupwordpress] < 3.14 (closed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-3034
|
BackUpWordPress [backupwordpress] < 3.14 (closed) |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Low
2.7
|
< 3.14
|
3.14 |
2024-04-26 |
—
|
CVE-2024-3034
The BackUpWordPress plugin through version 3.13 contains a directory traversal vulnerability in the hmbkp_directory_browse parameter that allows authenticated administrators to access files and directories outside the intended scope. An attacker with administrator-level permissions or higher could exploit this flaw to navigate the server's filesystem beyond the plugin's restricted boundaries. The vulnerability was patched in version 3.14.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings