Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 04 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Everestthemes
Everestthemes everest Backup Wordpress Wordpress wordpress |
|
| Vendors & Products |
Everestthemes
Everestthemes everest Backup Wordpress Wordpress wordpress |
Wed, 03 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Dec 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the process_status_unlink() function in all versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to delete the back-up progress files and cause a back-up to fail while it is in progress. | |
| Title | Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 - Missing Authorization to Unauthenticated Backup Failure | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:33:49.946Z
Reserved: 2025-09-11T21:54:46.884Z
Link: CVE-2025-10304
Updated: 2025-12-03T14:44:04.193Z
Status : Deferred
Published: 2025-12-03T04:15:58.613
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-10304
No data.
OpenCVE Enrichment
Updated: 2026-04-21T01:15:20Z