CVE-2023-7201
MEDIUMDescription
The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Is your site exposed to CVE-2023-7201?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| everestthemes | everest_backup |
References
Frequently Asked Questions
What is CVE-2023-7201? +
How severe is CVE-2023-7201? +
What products are affected by CVE-2023-7201? +
How do I check if I'm vulnerable to CVE-2023-7201? +
Related Vulnerabilities
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information …
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest themes GuCherry Blog allows Reflected XSS.This issue …
Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Path Traversal.This issue affects Everest Backup: from n/a through …