Description
WordPress Plugin DB Backup is prone to a directory traversal vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin DB Backup version 4.5 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Job Board by BestWebSoft Cross-Site Scripting (1.1.3)
SharePoint Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-5059)
WordPress Plugin Easy SVG Support Cross-Site Scripting (3.2.0)
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2017-8385)