The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
The vulnerability results from insufficient escaping of the 'options' parameter passed to the backuply_wp_clone_sql() function and the lack of proper preparation of the existing SQL query. An attacker can append additional SQL queries to existing queries, allowing unauthorized data extraction from the database. Exploitation requires an account with administrator privileges or higher.
An attacker with administrator privileges can extract sensitive information stored in the WordPress database, including user data, passwords (in hash form), and other confidential application content.
The Backuply plugin should be updated to a version higher than 1.3.4, which includes a fix (changeset 3151205 in the plugin repository). The update can be performed from the WordPress administration panel or by manually downloading the current version from the plugins.trac.wordpress.org repository.
Backuply – Backup, Restore, Migrate and Clone plugin for WordPress in all versions up to and including 1.3.4 (product: Softaculous Backuply).
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HSoftaculous Backuply
APPSoftaculous< 1.3.5
Related vulnerabilities
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in a...
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in...
Softaculous Webuzo — pominięcie uwierzytelnienia przez reset hasła
Błąd weryfikacji użytkownika w Softaculous Virtualizor WHMCS Reseller Module
Softaculous Webuzo contains a command injection in the password reset functionality. A remote, authenticated a...