CVE-2023-7165: Jetbackup
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors to leak backup files.
Affected products
- Jetbackup Jetbackup: before 2.0.9.9 (fixed in 2.0.9.9)
Published 2024-02-27. Last modified 2026-06-17.