The Church Admin WordPress plugin before 3.4.135 does not...
Moderate severity
Unreviewed
Published
Mar 29, 2022
to the GitHub Advisory Database
•
Updated Jul 5, 2023
Description
Published by the National Vulnerability Database
Mar 28, 2022
Published to the GitHub Advisory Database
Mar 29, 2022
Last updated
Jul 5, 2023
The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated attackers to repeatedly request the "refresh-backup" action, and simultaneously keep requesting a publicly accessible temporary file generated by the plugin in order to disclose the final backup filename, which can then be fetched by the attacker to download the backup of the plugin's DB data
References