#VU67167 Improper Authorization in BackupBuddy - CVE-2022-31474
Published: September 12, 2022 / Updated: October 21, 2022
BackupBuddy
iThemes
Description
The vulnerability allows a remote attacker to download arbitrary files from the server.
The vulnerability exists due to missing authorization for the feature responsible for remote downloading remote backups. A remote non-authenticated attacker can download arbitrary files from the server.
Note, the vulnerability is being actively exploited in the wild.