CVE-2024-13910 - WordPress Database Backup and Check Tables Automated With Scheduler Plugin File Deletion Vulnerability (Arbitrary File Deletion)
CVE ID : CVE-2024-13910 Published : March 1, 2025, 9:15 a.m. | 2 hours, 14 minutes ago Description : The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'database_backup_ajax_delete' function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The vulnerability was partially patched in version 2.36. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Published : March 1, 2025, 9:15 a.m. | 2 hours, 14 minutes ago
Description : The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'database_backup_ajax_delete' function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The vulnerability was partially patched in version 2.36.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...