Everest Backup WordPress Plugin Missing Authorization Vulnerability Allows Unauthenticated Backup Interference

Vulnerability

A vulnerability exists in the Everest Backup WordPress plugin, specifically in versions through 2.3.8. The issue arises from a missing capability check in the process_status_unlink() function, which allows unauthenticated users to delete backup progress files. This deletion can cause ongoing backup processes to fail.

Impact

Exploitation of this vulnerability can disrupt active backup processes, causing them to fail prematurely.

Reproduction

The vulnerability can be reproduced by sending a request to the 'wp_ajax_everest_backup_process_status_unlink' action without the necessary authorization. This can be done by an unauthenticated user, as the action is available to both authenticated and non-authenticated users.

Remediation

Users are advised to update the Everest Backup WordPress plugin to version 2.3.9 or later.

Added: Dec 3, 2025, 4:19 AM
Updated: Dec 3, 2025, 4:19 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
8.6
remediation
7.7
relevance
1.3
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.