CyberRota Analysis
AI-GeneratedThe JetBackup plugin for WordPress prior to version 3.1.23.5 contains a vulnerability that allows a subscriber-level user to obtain administrator privileges during site restoration or migration due to insufficient verification of user roles and capabilities. This flaw poses a significant security risk, as it can lead to unauthorized access and potential site compromise. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity risk.
Original NVD Description
The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site.