Backup Migration <= 2.1.5.1 - Authenticated (Administrator+) OS Command Injection via 'file' Parameter
high
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `restoreBackup()` AJAX handler. The handler applies `esc_attr()` — an HTML-context sanitizer that does not strip shell metach...
- CVSS:
- 7.2
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.5.2
- Disclosed:
- Aug 4, 2026
CVE-2026-7693 on NVD →
BackupBliss – Backup & Migration with Free Cloud Storage <= 2.1.1 - Unauthenticated Information Exposure
medium
The BackupBliss – Backup & Migration with Free Cloud Storage plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.2
- Disclosed:
- Apr 8, 2026
CVE-2026-39480 on NVD →
Backup Migration <= 2.0.0 - Missing Authorization to Unauthenticated Backup Upload to Offline Storage
medium
The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to a missing capability check on the 'initializeOfflineAjax' function and lack of proper nonce verification. The endpoint only validates against hardcoded tokens which are publicly e...
- CVSS:
- 5.3
- Affected:
- up to 2.0.0
- Fixed in:
- 2.1.0
- Disclosed:
- Apr 6, 2026
CVE-2025-14944 on NVD →
Backup Migration [backup-backup] < 2.0.0
unknown
[en] The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication.
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Nov 24, 2025
CVE-2025-12394 on NVD →
Backup Migration <= 1.4.9 - Information Exposure to Unauthenticated Back-up Download
high
The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via an exposed log file containing paths to backups. This makes it possible for unauthenticated attackers to extract sensitive data including files like wp-config.php.
- CVSS:
- 7.5
- Affected:
- up to 1.4.9
- Fixed in:
- 2.0.0
- Disclosed:
- Nov 3, 2025
CVE-2025-12394 on NVD →
Backup Migration [backup-backup] < 1.4.6.1
unknown
[en] The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of...
- Affected:
- up to 1.4.6.1
- Fixed in:
- 1.4.6.1
- Disclosed:
- Jan 4, 2025
CVE-2024-10932 on NVD →
Backup Migration <= 1.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialize_replace'
high
The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a PO...
- CVSS:
- 8.8
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.6.1
- Disclosed:
- Jan 3, 2025
CVE-2024-10932 on NVD →
Backup Migration [backup-backup] < 1.2.8
unknown
[en] Missing Authorization vulnerability in social share pro Social Share Icons & Social Share Buttons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.5.7.
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.8
- Disclosed:
- Dec 13, 2024
CVE-2023-38514 on NVD →
Backup Migration [backup-backup] < 1.4.4
unknown
[en] Insertion of Sensitive Information into Log File vulnerability in Inisev Backup Migration.This issue affects Backup Migration: from n/a through 1.4.3.
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Apr 18, 2024
CVE-2024-32686 on NVD →
Backup Migration <= 1.4.3 - Information Exposure via Log Files
medium
The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.3 via log files. This makes it possible for unauthenticated attackers to extract potentially sensitive information via log files.
- CVSS:
- 5.3
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Apr 17, 2024
CVE-2024-32686 on NVD →
Inisev Analyst Module <= Various Versions - Missing Authorization
medium
Multiple plugins and/or themes by Inisev for WordPress are vulnerable to unauthorized access due to a missing capability check on several functions in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.2
- Disclosed:
- Apr 10, 2024
CVE-2024-31435 on NVD →
Backup Migration [backup-backup] < 1.3.7
unknown
[en] The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated attackers to download back-up files w...
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7
- Disclosed:
- Jan 11, 2024
CVE-2023-6266 on NVD →
Backup Migration [backup-backup] < 1.3.6
unknown
[en] The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Jan 1, 2024
CVE-2023-6271 on NVD →
Backup Migration [backup-backup] < 1.4.0
unknown
[en] The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system.
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.0
- Disclosed:
- Dec 23, 2023
CVE-2023-7002 on NVD →
Backup Migration [backup-backup] < 1.4.0
unknown
[en] The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers to delete arbitrary fil...
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.0
- Disclosed:
- Dec 23, 2023
CVE-2023-6972 on NVD →
Backup Migration [backup-backup] >= 1.0.8 - <= 1.3.9
unknown
[en] The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. NOTE: Successful exploitation of this vulnerability...
- Affected:
- 1.0.8 – 1.3.9
- Fixed in:
- 1.3.9
- Disclosed:
- Dec 23, 2023
CVE-2023-6971 on NVD →
Backup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File Deletion
critical
The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers to delete arbitrary files, i...
- CVSS:
- 9.8
- Affected:
- up to 1.3.9
- Fixed in:
- 1.4.0
- Disclosed:
- Dec 22, 2023
CVE-2023-6972 on NVD →
Backup Migration 1.0.8 - 1.3.9 - Remote File Inclusion via content-dir
high
The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. NOTE: Successful exploitation of this vulnerability requ...
- CVSS:
- 8.1
- Affected:
- 1.0.8 – 1.3.9
- Fixed in:
- 1.4.0
- Disclosed:
- Dec 22, 2023
CVE-2023-6971 on NVD →
Backup Migration <= 1.3.9 - Authenticated (Admin+) OS Command Injection via url
high
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system.
- CVSS:
- 7.2
- Affected:
- up to 1.3.9
- Fixed in:
- 1.4.0
- Disclosed:
- Dec 22, 2023
CVE-2023-7002 on NVD →
Backup Migration [backup-backup] < 1.3.8
unknown
[en] The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. Th...
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.8
- Disclosed:
- Dec 15, 2023
CVE-2023-6553 on NVD →
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
critical
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This ma...
- CVSS:
- 9.8
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.8
- Disclosed:
- Dec 11, 2023
CVE-2023-6553 on NVD →
Backup Migration <= 1.3.5 - Unauthenticated Sensitive Information Exposure
critical
The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5. This makes it possible for unauthenticated attackers to extract database backups leading to the potential for a complete site takeover.
- CVSS:
- 9.8
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.6
- Disclosed:
- Dec 7, 2023
CVE-2023-6271 on NVD →
Backup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure
high
The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated attackers to download back-up files which...
- CVSS:
- 7.5
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.7
- Disclosed:
- Nov 30, 2023
CVE-2023-6266 on NVD →
Backup Migration [backup-backup] < 1.3.0
unknown
Update the WordPress Backup Migration plugin to the latest available version (at least 1.3.0).
Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Backup Migration Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under...
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- Sep 6, 2023
Backup Migration <= 1.2.9 - Cross-Site Request Forgery
medium
The Backup Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.9. This is due to missing nonce validation on the ajax() function, or BMI_Ajax class. This makes it possible for unauthenticated attackers to control any of the plugin's settings, and restore/dele...
- CVSS:
- 4.3
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- Sep 5, 2023
Backup Migration [backup-backup] < 1.3.0
unknown
The Backup Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.9. This is due to missing nonce validation on the ajax() function, or BMI_Ajax class. This makes it possible for unauthenticated attackers to control any of the plugin's settings, and restore/dele...
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- Sep 5, 2023
Backup Migration [backup-backup] < 1.2.8
unknown
[en] Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attack...
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.8
- Disclosed:
- Jul 28, 2023
CVE-2023-3977 on NVD →
Backup Migration [backup-backup] < 1.2.8
unknown
[en] Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permission...
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.8
- Disclosed:
- Jul 28, 2023
CVE-2023-0958 on NVD →
Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function
medium
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, su...
- CVSS:
- 4.3
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.8
- Disclosed:
- Jul 27, 2023
CVE-2023-0958 on NVD →
Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function
medium
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers t...
- CVSS:
- 4.3
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.8
- Disclosed:
- Jul 27, 2023
CVE-2023-3977 on NVD →
Backup Migration <= 1.2.8 - Sensitive Information Exposure
high
The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.8 via config and log files in the wp-content/backup-migration/ folder. This can allow unauthenticated attackers to extract sensitive data in certain configurations, including the site administ...
- CVSS:
- 7.5
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.9
- Disclosed:
- May 10, 2023
CVE-2023-54346 on NVD →
Backup Migration [backup-backup] < 1.2.9
unknown
The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.8 via config and log files in the wp-content/backup-migration/ folder. This can allow unauthenticated attackers to extract sensitive data in certain configurations, including the site administ...
- Affected:
- up to 1.2.9
- Fixed in:
- 1.2.9
- Disclosed:
- May 10, 2023
Backup Migration [backup-backup] < 1.1.6
unknown
[en] Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions.
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- Nov 19, 2021
CVE-2021-36884 on NVD →
Backup Migration <= 1.1.5 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions.
- CVSS:
- 5.5
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.6
- Disclosed:
- Nov 17, 2021
CVE-2021-36884 on NVD →
Backup Migration [backup-backup] < 1.3.0
unknown
The Backup Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.9. This is due to missing nonce validation on the ajax() function, or BMI_Ajax class. This makes it possible for unauthenticated attackers to control any of the plugin's settings, and restore...
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
Backup Migration [backup-backup] < 1.4.2
unknown
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.2
CVE-2024-31435 on NVD →