Description
WordPress Plugin Simple Backup is prone to multiple vulnerabilities, including arbitrary file deletion and arbitrary file download vulnerabilities. An attacker may leverage these issues to delete arbitrary files or to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin Simple Backup version 2.7.11 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
Dot CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-37033)
WordPress Ultimate Member Plugin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-31216)
Oracle JRE CVE-2023-21835 Vulnerability (CVE-2023-21835)
WordPress Plugin Tickera-WordPress Event Ticketing Cross-Site Request Forgery (3.5.1.0)
Oracle Database Server CVE-2009-1963 Vulnerability (CVE-2009-1963)