Description
WordPress Plugin BackupBuddy is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin BackupBuddy version 2.2.28 is vulnerable; other versions may also be affected.
Remediation
Make sure that the file 'importbuddy.php' is removed from the root of the website
References
http://packetstormsecurity.com/files/120923/Backupbuddy-2.2.4-Sensitive-Data-Exposure.html
http://archives.neohapsis.com/archives/fulldisclosure/2013-03/0205.html
Related Vulnerabilities
WordPress Plugin Category List Portfolio Page TimThumb Arbitrary File Upload (1.2.3)
Oracle Database Server CVE-2014-4310 Vulnerability (CVE-2014-4310)
Oracle Application Server Other Vulnerability (CVE-2005-3204)
Drupal Other Vulnerability (CVE-2006-1225)
WordPress Plugin Fancy Product Designer-WooCommerce Cross-Site Scripting (3.4.1)