Everest Backup
cpe:2.3:a:everestthemes:everest_backup:*:*:*:*:wordpress:*:*
- <= 2.3.8
A vulnerability exists in the Everest Backup WordPress plugin, specifically in versions through 2.3.8. The issue arises from a missing capability check in the process_status_unlink() function, which allows unauthenticated users to delete backup progress files. This deletion can cause ongoing backup processes to fail.
Exploitation of this vulnerability can disrupt active backup processes, causing them to fail prematurely.
The vulnerability can be reproduced by sending a request to the 'wp_ajax_everest_backup_process_status_unlink' action without the necessary authorization. This can be done by an unauthenticated user, as the action is available to both authenticated and non-authenticated users.
Users are advised to update the Everest Backup WordPress plugin to version 2.3.9 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.