Cyber Resilience

CVE-2023-7201

Everestthemes Everest Backup ≤ 2.2.5

Public PoC
Published
15 April 2024
Modified
08 May 2025
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
EPSS Score 0.0065 48th percentile
Risk Priority 49 floored blend · peak EPSS

Summary

CVE-2023-7201 is a medium-severity an unspecified weakness vulnerability in Everestthemes Everest Backup. Its CVSS base score is 6.5 (Medium).

Operationally, ranked at the 48th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example…

more

in multisite setup)

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-52185Same product: Everestthemes Everest Backup
CVE-2025-62992Same product: Everestthemes Everest Backup
CVE-2024-10028Same product: Everestthemes Everest Backup
CVE-2023-27421Same vendor: Everestthemes
CVE-2023-27419Same vendor: Everestthemes
CVE-2023-41235Same vendor: Everestthemes
CVE-2023-41237Same vendor: Everestthemes
CVE-2024-32531Same vendor: Everestthemes
CVE-2023-27420Same vendor: Everestthemes
CVE-2023-27412Same vendor: Everestthemes

Affected Assets

everestthemes
everest backup
≤ 2.2.5

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References