The WP STAGING Pro WordPress Backup Plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 6.1.2 due to missing capability checks on the getOutdatedPluginsRequest() function. This makes it possible for unauthenticated attackers to reveal outdated installed active or inactive plugins.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Apr 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WP STAGING Pro WordPress Backup Plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 6.1.2 due to missing capability checks on the getOutdatedPluginsRequest() function. This makes it possible for unauthenticated attackers to reveal outdated installed active or inactive plugins. | |
Title | WP Staging Pro <= 6.1.2 - Unauthenticated Information Exposure via getOutdatedPluginsRequest Function | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-04-16T14:34:09.724Z
Reserved: 2025-04-01T21:47:26.857Z
Link: CVE-2025-3104

Updated: 2025-04-16T14:12:52.590Z

Status : Awaiting Analysis
Published: 2025-04-16T09:15:28.030
Modified: 2025-04-16T13:25:37.340
Link: CVE-2025-3104

No data.