BackupBuddy <= 8.8.2 - Reflected Cross-Site Scripting
medium
The BackupBuddy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting several parameters in versions up to, and including, 8.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c...
- CVSS:
- 6.1
- Affected:
- up to 8.8.2
- Fixed in:
- 8.8.3
- Disclosed:
- Jan 30, 2023
CVE-2022-4897 on NVD →
BackupBuddy 8.5.8.0 - 8.7.4.1 - Arbitrary File Download
high
The BackupBuddy plugin for WordPress is vulnerable to unauthenticated arbitrary file downloads via the 'local-download' found in the backupbuddy_local_download() function in versions 8.5.8.0 to 8.7.4.1. This is due to a missing capability check and nonce check on the affected function that is called via an admin_init h...
- CVSS:
- 7.5
- Affected:
- 8.5.8.0 – 8.7.4.1
- Fixed in:
- 8.7.5
- Disclosed:
- Sep 6, 2022
CVE-2022-31474 on NVD →
BackupBuddy < 3.0 - Authentication Bypass
critical
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1) direct request, (2) step=1 request, (3) step=2 or step...
- CVSS:
- 9.8
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Mar 24, 2013
CVE-2013-2741 on NVD →
BackupBuddy < 3.0 - Authentication Bypass
critical
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after completing a restore operation, which makes it easier for remote attackers to obtain access via subsequent requests to this script.
- CVSS:
- 9.8
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Mar 24, 2013
CVE-2013-2742 on NVD →
BackupBuddy < 3.0 - Authentication Bypass
critical
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via a crafted integer in the step parameter.
- CVSS:
- 9.8
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Mar 24, 2013
CVE-2013-2743 on NVD →
BackupBuddy <= 2.2.28 - Sensitive Information Disclosure
medium
The BackupBuddy plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.2.28 via a step 0 phpinfo action, which calls the phpinfo function. This can allow remote attackers to extract configuration information.
- CVSS:
- 5.3
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Mar 24, 2013
CVE-2013-2744 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database