CVE-2023-7164: Inpsyde Backwpup
High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.
The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.
Affected products
- Inpsyde Backwpup: before 4.0.4 (fixed in 4.0.4)
Published 2024-04-08. Last modified 2026-06-17.