Description
WordPress Plugin BackWPup is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently brute force backup files location. WordPress Plugin BackWPup version 3.4.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.4.2 or latest
References
Related Vulnerabilities
WordPress Plugin Multi Feed Reader SQL Injection (2.2.3)
Plone CMS Improper Input Validation Vulnerability (CVE-2013-4199)
WordPress Plugin CM Pop-Up banners for WordPress Cross-Site Scripting (1.4.10)
WordPress Plugin WP Construction Mode Cross-Site Request Forgery (1.8)
Django Improper Input Validation Vulnerability (CVE-2014-0480)