CVE-2021-24174
The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups.
- Affected products
- Database Backup
- Database-backups Project Database-backups
- ≤ 1.2.2.6
- Fix
- Available
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 3.2% (88th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2021-04-05
CVE-2021-24174 at NVD
4 known exploits for CVE-2021-24174
Proof-of-concept code and exploit modules indexed by Sploitus