The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Metrics
Affected Vendors & Products
References
History
Thu, 08 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Everestthemes
Everestthemes everest Backup |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:everestthemes:everest_backup:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Everestthemes
Everestthemes everest Backup |
Fri, 09 Aug 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published: 2024-04-15T05:00:01.572Z
Updated: 2024-08-09T20:01:33.240Z
Reserved: 2024-01-02T22:54:43.113Z
Link: CVE-2023-7201
Updated: 2024-08-02T08:57:34.095Z
Status : Analyzed
Published: 2024-04-15T05:15:14.583
Modified: 2025-05-08T16:53:40.513
Link: CVE-2023-7201
No data.