The WordPress Backup & Migration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wp_mgdp_populate_popup function in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with subscriber access or above, to invoke this function and access log files maintained by the plugin. Additionally, the file name is user-provided and not properly sanitized, which allows attackers to read arbitrary log files on the file system.
History

Wed, 08 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
Title WordPress Backup & Migration <= 1.4.8 - Missing Authorization to Directory Traversal
Weaknesses CWE-862

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:45:31.512Z

Reserved: 2024-04-09T19:09:13.577Z

Link: CVE-2024-3546

cve-icon Vulnrichment

Updated: 2024-08-01T20:12:07.631Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-02T17:15:26.587

Modified: 2026-04-08T18:21:26.990

Link: CVE-2024-3546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.