CVE-2023-7165

The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors to leak backup files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jetbackup:jetbackup:*:*:*:*:*:wordpress:*:*

History

01 May 2025, 14:56

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/ad1ef4c5-60c1-4729-81dd-f626aa0ce3fe/ - () https://wpscan.com/vulnerability/ad1ef4c5-60c1-4729-81dd-f626aa0ce3fe/ - Exploit, Third Party Advisory
First Time Jetbackup
Jetbackup jetbackup
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:jetbackup:jetbackup:*:*:*:*:*:wordpress:*:*

Information

Published : 2024-02-27 09:15

Updated : 2025-05-01 14:56


NVD link : CVE-2023-7165

Mitre link : CVE-2023-7165

CVE.ORG link : CVE-2023-7165


JSON object : View

Products Affected

jetbackup

  • jetbackup