CVE-2026-14503
בינונית 6.5
תיאור (מקור, אנגלית)
The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract force generation of a full-site backup archive written to a publicly accessible directory, exposing wp-config.php database credentials, WordPress secret salts, and the complete PHP source tree. The resulting archive is deposited in the plugin's unprotected tmp/ directory at a predictable URL, making the extracted data accessible to unauthenticated visitors once the backup is triggered.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-5/8/2026
- CWE
- CWE-200
קישורים
- https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/Pcloud/…
- https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-…
- https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-…
- https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-…
- https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-…
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3597399%40pcloud-wp…
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0b301c6e-a3c5-4435-9…