GHSA-5547-r7f3-wcccMediumCVSS 6.6
The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of...
🔗 CVE IDs covered (1)
📋 Description
The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution.