Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
webtoffee backup and migration vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2023-5737
The WordPress Backup & Migration WordPress plugin prior to 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.
Webtoffee Backup And Migration
5.4
CVSSv3
CVE-2023-5738
The WordPress Backup & Migration WordPress plugin prior to 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.
Webtoffee Backup And Migration
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
hard-coded
CVE-2024-27202
NULL pointer dereference
CVE-2024-28075
CVE-2024-33608
CVE-2024-28889
CVE-2024-34572
template injection
CVE-2024-34351
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started