PT-2026-84611 · WordPress · Jetbackup
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JetBackup WordPress plugin versions prior to 3.1.23.5
Description
An issue exists where the plugin fails to verify the role or capabilities of an account preserved during a restore or migration process before granting it administrator privileges. This allows a user with subscriber-level permissions to escalate their privileges to administrator status after the site owner performs a site restore or migration.
Recommendations
Update JetBackup WordPress plugin to version 3.1.23.5 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jetbackup