← console
voxell vciy

CVE-2024-56067: WordPress WP SuperBackup plugin <= 2.3.3 - Unauthenticated Backup File Download Vulnerability

MATERIAL

Exploit probability fell from 0.65072 to 0.10034, crossing 0.50. The crossing is the event; the daily drift either side of it is not.

CVE record loaded 2026-09-20.

What to do now held facts and links

  1. Upgrade to 2.4 or later CVE record
  2. Record your decision, dated and frozen with today's evidence: patch by a date · mitigated by a compensating control · deferred · accepted the risk · not affected
  3. Check your version against the ranges this record publishes.

What it is stated by the CNA

Missing Authorization vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

weakness
CWE-862 Missing Authorization
affected
azzaroco WP SuperBackup
versions
azzaroco WP SuperBackup <= 2.3.3
fixed in
2.4
severity
7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
assigned by
Patchstack
published
2024-12-31

check us patchstack.com

Exploit code held, dated

exploit code
1 public proof-of-concept repository, first seen 2025-01-09 (PoC-in-GitHub).

What moved held, dated

dateEPSSevent
1 Jan 20250.00043
17 Mar 20250.00694scoring model v2025.03.14
19 Mar 20250.04926
20 Mar 20250.00694
8 Feb 20260.55898crossed 0.10, crossed 0.50
2 Apr 20260.40509crossed 0.50
29 Apr 20260.62319crossed 0.50
22 May 20260.65072
15 Jun 20260.10034crossed 0.50 · scoring model v2026.06.15

33 observations held. A step marked with a scoring model moved because the measurement was replaced, not because the vulnerability changed.

Outside the record researched, cited

This section reads the record's references and adds cited findings from outside it. It needs an account. Everything above is held facts and is complete without it.

Sign in to add the researched section

What would change this brief held, dated

CISA KEV
Not listed in the catalogue we hold. A listing changes this brief.
exploit probability
0.10 on 2026-06-15 (FIRST's EPSS, a probability and not evidence of exploitation). Next band line: 50% (0.50). Crossing a line changes this brief.
fix
Held: 2.4 (CVE record, loaded 2026-09-20). A newer fix from the CNA or OSV changes this brief.

Watch this CVE What counts as a move

How to check this

Every value above is held with two dates: when it was true upstream (as_of) and when we recorded it (tx_from). Re-derive the exploit probability as it stood on any date:

SELECT value, source, source_version, as_of, tx_from
FROM volatile_valid_as_of('CVE-2024-56067', '2026-10-03T23:59:59.999999Z', now());

Identity above is quoted from the CVE Program record, corpus cvelistv5_20260920, recorded 30 Sep 2026.