Medium severity4.3NVD Advisory· Published Nov 27, 2023· Updated Jun 17, 2026
CVE-2023-5737
CVE-2023-5737
Description
The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:webtoffee:backup_and_migration:*:*:*:*:*:wordpress:*:*Range: <1.4.4
- Range: <1.4.4
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/c761c67c-eab8-4e1b-a332-c9a45e22bb13nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.