Everest Backup reports: why nonces do not establish authorization

← All articles

Everest Backup reports: why nonces do not establish authorization

Correction: the earlier article dismissed a reported backup-export issue because a nonce was present. That reasoning was incorrect. It also claimed an investigation by our team without supporting evidence; that claim has been removed.

What a nonce does

A WordPress nonce helps protect requests against cross-site request forgery. It does not prove that a user has permission to export a backup. WordPress explicitly warns against using nonces for authentication or authorization. Sensitive actions also need an appropriate capability check, such as current_user_can(), and checks on the requested resource.

How to assess a report

Identify the exact plugin, affected versions, endpoint, required user role and vendor advisory. Check whether a low-privilege account can obtain a nonce and request someone else's backup. Test only on an authorized, isolated copy with non-sensitive data. This article does not establish a specific affected version or declare the Everest Backup report a false positive.

Practical next steps

Keep backup files inaccessible to unauthorized visitors, limit export permissions and review downloads for unexpected access. Use vendor-supported updates. If exposure is suspected, follow your incident-response process; applying an update alone does not undo a prior disclosure.

Sources and further reading