JetBackup WordPress plugin <= 2.0.9.9 does not use index files to prevent directory listing in certain configurations, letting malicious actors leak backup files, exploit requires access to the web server.
id: CVE-2023-7165
info:
name: JetBackup <= 2.0.9.7 - Sensitive Information Exposure via Directory
...