CyberRota Analysis
AI-GeneratedThe JetBackup WordPress plugin prior to version 3.1.23.5 lacks proper multisite authorization checks, enabling non-Super Admin network administrators to access and download full backups of all sites within the network, including sensitive data and shared webroot. This vulnerability poses a significant risk to data confidentiality and integrity across the entire WordPress multisite installation. WordPress administrators, particularly those managing multisite environments, should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot.