BackWPup WordPress plugin < 4.0.4 contains a directory listing vulnerability caused by lack of access restrictions in its temporary backup folder, letting unauthenticated attackers download site backups, exploit requires no authentication.
id: CVE-2023-7164
info:
name: WordPress BackWPup < 4.0.4 - Backup File Disclosure
author: 0x_Ak
...