The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'everest_process_status' AJAX action in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated attackers to retrieve back-up file locations that can be subsequently accessed and downloaded. This does require a back-up to be running in order for an attacker to retrieve the back-up location.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a minimal proof-of-concept for CVE-2025-11380 affecting the Everest Backup WordPress plugin (<= 2.3.5), described as unauthenticated backup access. Structure: (1) README.md with a brief CVE description; (2) cve-2025-11380.py, a Python script using requests to repeatedly poll the WordPress AJAX endpoint /wp-admin/admin-ajax.php?action=everest_process_status without authentication (TLS verification disabled). The script waits until a backup is detected (non-empty JSON response), then continues polling until the JSON includes data.result.zipurl. It prints the discovered backup URL and, if invoked with -d/--download, performs a direct GET to that URL and saves the returned content locally under the URL’s basename. Overall purpose: exploit an information disclosure/authorization flaw to obtain (and optionally download) a backup archive while a backup is in progress.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.