Database Backups <= 1.2.2.6 - Cross-Site Request Forgery
highThe Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups.
- CVSS:
- 8.1
- Affected:
- up to 1.2.2.6
- Fix:
- No patched version reported
- Disclosed:
- Mar 10, 2021