plugin

Backuply Vulnerabilities

10 known security issues reported for the Backuply WordPress plugin. Most recent disclosed Sep 25, 2025.

1 critical 1 high 3 medium

Running Backuply on your site? Check whether your installed version is affected.

Scan your site free

Backuply – Backup, Restore, Migrate and Clone <= 1.4.8 - Authenticated (Admin+) Arbitrary File Deletion

medium

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete backup functionality in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Administrator-level access and...

CVSS:
6.5
Affected:
up to 1.4.8
Fixed in:
1.4.9
Disclosed:
Sep 25, 2025

CVE-2025-10307 on NVD →

Backuply &#8211; Backup, Restore, Migrate and Clone [backuply] < 1.3.5

unknown

[en] The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...

Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
Sep 14, 2024

CVE-2024-8669 on NVD →

Backuply – Backup, Restore, Migrate and Clone <= 1.3.4 - Authenticated (Admin+) SQL Injection

critical

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t...

CVSS:
9.1
Affected:
up to 1.3.4
Fixed in:
1.3.5
Disclosed:
Sep 13, 2024

CVE-2024-8669 on NVD →

Backuply &#8211; Backup, Restore, Migrate and Clone [backuply] < 1.2.8

unknown

[en] The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.7 via the backup_name parameter in the backuply_download_backup function. This makes it possible for attackers to have an account with only activate_plugins capabili...

Affected:
up to 1.2.8
Fixed in:
1.2.8
Disclosed:
Mar 16, 2024

CVE-2024-2294 on NVD →

Backuply – Backup, Restore, Migrate and Clone <= 1.2.7 - Authenticated (Admin+) Directory Traversal

medium

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.7 via the backup_name parameter in the backuply_download_backup function. This makes it possible for attackers to have an account with only activate_plugins capability to...

CVSS:
4.9
Affected:
up to 1.2.7
Fixed in:
1.2.8
Disclosed:
Mar 15, 2024

CVE-2024-2294 on NVD →

Backuply &#8211; Backup, Restore, Migrate and Clone [backuply] < 1.2.7

unknown

[en] The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.5. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result i...

Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Feb 9, 2024

CVE-2024-0842 on NVD →

Backuply - Backup, Restore, Migrate and Clone <= 1.2.6 - Denial of Service

high

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.6. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result in the...

CVSS:
7.5
Affected:
up to 1.2.6
Fixed in:
1.2.7
Disclosed:
Feb 8, 2024

CVE-2024-0842 on NVD →

Backuply &#8211; Backup, Restore, Migrate and Clone [backuply] < 1.2.4

unknown

[en] The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.3 via the node_id parameter in the backuply_get_jstree function. This makes it possible for attackers with administrator privileges or higher to read the contents of...

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Jan 27, 2024

CVE-2024-0697 on NVD →

Backuply – Backup, Restore, Migrate and Clone <= 1.2.3 - Authenticated (Administrator+) Directory Traversal

medium

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.3 via the node_id parameter in the backuply_get_jstree function. This makes it possible for attackers with administrator privileges or higher to read the contents of arbi...

CVSS:
6.5
Affected:
up to 1.2.3
Fixed in:
1.2.4
Disclosed:
Jan 26, 2024

CVE-2024-0697 on NVD →

Backuply &#8211; Backup, Restore, Migrate and Clone [backuply] < 1.4.9

unknown
Affected:
up to 1.4.9
Fixed in:
1.4.9

CVE-2025-10307 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database