PT-2026-60708 · Ploudapp+1 · Pcloud Backup+1
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
pCloud WP Backup versions prior to 2.0.4
Description
An issue exists in the
wp2pcl ajax process request inner function that allows authenticated users with subscriber-level access or higher to force the generation of a full-site backup archive. This archive is stored in a publicly accessible tmp/ directory at a predictable URL, enabling unauthenticated visitors to access sensitive data. The exposed information includes the wp-config.php file containing database credentials, WordPress secret salts, and the entire PHP source tree.Recommendations
Update pCloud WP Backup to version 2.0.4 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pcloud Backup
Pcloud-Wp-Backup