Zero-day vulnerability in BackupBuddy

Improper Authorization
CVE-2022-31474

Vulnerability details

Advisory: SB2022091201 - Arbitrary file read in BackupBuddy WordPress plugin

Vulnerable component: BackupBuddy

CVE-ID: CVE-2022-31474

CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C

CWE-ID: CWE-285 - Improper Authorization

Description:

The vulnerability allows a remote attacker to download arbitrary files from the server.

The vulnerability exists due to missing authorization for the feature responsible for remote downloading remote backups. A remote non-authenticated attacker can download arbitrary files from the server. 

Note, the vulnerability is being actively exploited in the wild.

External links:

https://ithemes.com/blog/wordpress-vulnerability-report-special-edition-september-6-2022-backupbuddy/