← voltar
CVE-2025-10306

Backup Bolt <= 1.4.1 - Authenticated (Admin+) Arbitrary File Download

CVSS 3.8 LOWEPSS 0.3%CWE-73
Vexday Risk Score
8Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 3.8EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
03 out 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4.1 via the process_backup_batch() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to download directories outside of the webroot and write backup zip files to arbitrary locations.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Produtos afetados
backupbolt · Backup Bolt

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →