CVE-2018-19456

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
07/05/2019
Last modified:
08/05/2019

Description

The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive information from server folders and files, as demonstrated by download.sql.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wplaunchpad:wpbackupplus:*:*:*:*:*:wordpress:*:* 2018-11-22 (including)
cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*