Input validation vulnerability in Backup by Supsystic 2.3.11

The Backup by Supsystic plugin for WordPress is a security risk. This plugin, which is used in versions up to and including 2.3.11, has a vulnerability that allows attackers to both download and delete any file on the vulnerable server. This vulnerability is due to path traversal attacks and missing CSRF checks. Even attackers who are not authenticated as an administrator can delete files.

Detected in:

Backup by Supsystic open vulnerable versions: >= * <= 2.3.11

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.