plugin

Backupbuddy Vulnerabilities

6 known security issues reported for the Backupbuddy WordPress plugin. Most recent disclosed Jan 30, 2023.

3 critical 1 high 2 medium

Running Backupbuddy on your site? Check whether your installed version is affected.

Scan your site free

BackupBuddy <= 8.8.2 - Reflected Cross-Site Scripting

medium

The BackupBuddy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting several parameters in versions up to, and including, 8.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c...

CVSS:
6.1
Affected:
up to 8.8.2
Fixed in:
8.8.3
Disclosed:
Jan 30, 2023

CVE-2022-4897 on NVD →

BackupBuddy 8.5.8.0 - 8.7.4.1 - Arbitrary File Download

high

The BackupBuddy plugin for WordPress is vulnerable to unauthenticated arbitrary file downloads via the 'local-download' found in the backupbuddy_local_download() function in versions 8.5.8.0 to 8.7.4.1. This is due to a missing capability check and nonce check on the affected function that is called via an admin_init h...

CVSS:
7.5
Affected:
8.5.8.0 – 8.7.4.1
Fixed in:
8.7.5
Disclosed:
Sep 6, 2022

CVE-2022-31474 on NVD →

BackupBuddy < 3.0 - Authentication Bypass

critical

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1) direct request, (2) step=1 request, (3) step=2 or step...

CVSS:
9.8
Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Mar 24, 2013

CVE-2013-2741 on NVD →

BackupBuddy < 3.0 - Authentication Bypass

critical

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after completing a restore operation, which makes it easier for remote attackers to obtain access via subsequent requests to this script.

CVSS:
9.8
Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Mar 24, 2013

CVE-2013-2742 on NVD →

BackupBuddy < 3.0 - Authentication Bypass

critical

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via a crafted integer in the step parameter.

CVSS:
9.8
Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Mar 24, 2013

CVE-2013-2743 on NVD →

BackupBuddy <= 2.2.28 - Sensitive Information Disclosure

medium

The BackupBuddy plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.2.28 via a step 0 phpinfo action, which calls the phpinfo function. This can allow remote attackers to extract configuration information.

CVSS:
5.3
Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Mar 24, 2013

CVE-2013-2744 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database