Improper access control in WP Database Backup - #VU18808
Published: June 17, 2019 / Updated: June 18, 2019
WP Database Backup
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions when a nonce check was required when the "wp-database-backup" page of a site’s admin dashboard was accessed. A remote attacker can modify backup configuration settings, including list tables that are to be excluded from the backup.