Sceawere
Vulnerability Detail
CVE-2026-42413UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Sensitive Data Exposure
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 16h ago
- Vendor
- DaftPlug
- Product
- Snapshotify – All-in-One Backup & Restore & Migrate
- Attack Type
- CWE-201 Insertion of Sensitive Information Into Sent Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Sensitive Data Exposure in Snapshotify – All-in-One Backup & Restore & Migrate <= 1.3.2 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-06T09:17:54.170Z",
"pubdate": "2026-10-06T09:17:54.170Z",
"executiveSummary": "The Snapshotify – All-in-One Backup & Restore & Migrate plugin for WordPress, in versions 1.3.2 and below, contains a critical security vulnerability involving unauthenticated sensitive data exposure.\nThis vulnerability allows an unauthenticated remote attacker to access, download, or exfiltrate sensitive backup files and configuration data generated by the plugin without requiring any form of authentication or authorization.\nThe flaw stems from a lack of proper access control checks on the endpoints responsible for serving or managing backup archives.\nSuccessful exploitation poses a severe risk to the confidentiality of the entire WordPress installation, potentially exposing database credentials, full site content, user data, and system configurations.\nAn attacker can exploit this by directly crafting requests to accessible file paths, enabling unauthorized retrieval of sensitive information without prior knowledge or credentials.\nThis vulnerability highlights a significant failure in the security architecture of the plugin, effectively bypassing established WordPress authentication protocols and exposing the system to data breaches.",
"technicalDetails": "The vulnerability resides in the Snapshotify plugin's handling of requests directed toward its backup directory or associated file-management functions. In versions 1.3.2 and below, the plugin fails to implement sufficient verification of the requester's session or capability to access sensitive plugin-generated artifacts.\nThe root cause is an improper authorization check (or complete lack thereof) within the code responsible for processing requests for stored backup files. The plugin exposes a predictable or enumerable file path structure where backups are stored, and the server-side code fails to validate if the initiator of the request is an authenticated administrator or has the requisite 'manage_options' capability.\nThe exploitation flow begins with an attacker identifying the endpoint or the directory path used by Snapshotify to store backup archives. Because these files are often stored within the web-accessible directory structure of the WordPress installation, an attacker can bypass the intended plugin interface by making a direct GET request to the file URL.\nBecause the plugin does not enforce authentication checks, the server treats the request as a legitimate retrieval request and serves the file directly to the unauthenticated attacker. This circumvents WordPress security hooks that would otherwise restrict file access to authorized administrators only.\nThe post-exploitation impact is critical. Backup archives typically contain the complete database structure, including hashed passwords, session tokens, personal user information, and sensitive configuration files like wp-config.php. By successfully downloading these files, an attacker gains complete insight into the site's environment, which significantly facilitates further attacks such as full database takeover, lateral movement, or complete site compromise. The exposure does not require any specialized user interaction or complex script execution, making it a highly accessible target for automated scanners and malicious actors seeking to harvest data from vulnerable WordPress deployments."
}