Access violation vulnerability in WP STAGING WordPress Backup Plugin – Migration Backup Restore 3.4.3

The WP STAGING and WP STAGING Pro plugins for WordPress are at risk of exposing sensitive information. This can happen in versions up to 3.4.3 and 5.4.3, respectively, through the ajaxSendReport function. This could allow unauthorized individuals to access important data from a log file, such as system information and license keys (for the Pro version). To exploit this vulnerability, an administrator would have needed to use the ‘Contact Us’ feature and enable the “automatically submit log files” option.

Detected in:

WP STAGING Pro WordPress Backup Plugin fixed vulnerable versions: >= * <= 5.4.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.