CVE-2023-5737
Description
The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.
CWE
- (none)
Affected
- Unknown / WordPress Backup & Migration — v=0 <1.4.4 [affected]
CVSS
- (none)
References
- https://wpscan.com/vulnerability/c761c67c-eab8-4e1b-a332-c9a45e22bb13 exploit, vdb-entry, technical-description
Source
cvelistV5-main/cves/2023/5xxx/CVE-2023-5737.json