Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 21 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Everestthemes
Everestthemes everest Backup Wordpress Wordpress wordpress |
|
| Vendors & Products |
Everestthemes
Everestthemes everest Backup Wordpress Wordpress wordpress |
Tue, 14 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 11 Oct 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'everest_process_status' AJAX action in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated attackers to retrieve back-up file locations that can be subsequently accessed and downloaded. This does require a back-up to be running in order for an attacker to retrieve the back-up location. | |
| Title | Everest Backup <= 2.3.5 - Missing Authorization to Unauthenticated Information Exposure | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:04:51.324Z
Reserved: 2025-10-06T17:13:51.116Z
Link: CVE-2025-11380
Updated: 2025-10-14T13:42:25.070Z
Status : Deferred
Published: 2025-10-11T03:15:31.100
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-11380
No data.
OpenCVE Enrichment
Updated: 2026-04-22T12:45:17Z