Access violation vulnerability in WordPress Backup & Migration 1.4.8

The WordPress Backup & Migration plugin for WordPress has a security issue that could allow unauthorized people to access sensitive data. This is because the plugin doesn’t check for proper permissions when using a certain function, making it possible for even regular users to see log files. Furthermore, the plugin doesn’t properly clean up file names, which means attackers could potentially view any log file on the system.

Detected in:

WebToffee WP Backup and Migration fixed vulnerable versions:
WordPress Backup & Migration open vulnerable versions: >= * <= 1.4.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.