Backuply – Backup, Restore, Migrate and Clone <= 1.4.8 - Authenticated (Admin+) Arbitrary File Deletion
medium
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete backup functionality in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Administrator-level access and...
- CVSS:
- 6.5
- Affected:
- up to 1.4.8
- Fixed in:
- 1.4.9
- Disclosed:
- Sep 25, 2025
CVE-2025-10307 on NVD →
Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.3.5
unknown
[en] The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Sep 14, 2024
CVE-2024-8669 on NVD →
Backuply – Backup, Restore, Migrate and Clone <= 1.3.4 - Authenticated (Admin+) SQL Injection
critical
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t...
- CVSS:
- 9.1
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.5
- Disclosed:
- Sep 13, 2024
CVE-2024-8669 on NVD →
Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.2.8
unknown
[en] The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.7 via the backup_name parameter in the backuply_download_backup function. This makes it possible for attackers to have an account with only activate_plugins capabili...
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.8
- Disclosed:
- Mar 16, 2024
CVE-2024-2294 on NVD →
Backuply – Backup, Restore, Migrate and Clone <= 1.2.7 - Authenticated (Admin+) Directory Traversal
medium
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.7 via the backup_name parameter in the backuply_download_backup function. This makes it possible for attackers to have an account with only activate_plugins capability to...
- CVSS:
- 4.9
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.8
- Disclosed:
- Mar 15, 2024
CVE-2024-2294 on NVD →
Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.2.7
unknown
[en] The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.5. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result i...
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Feb 9, 2024
CVE-2024-0842 on NVD →
Backuply - Backup, Restore, Migrate and Clone <= 1.2.6 - Denial of Service
high
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.6. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result in the...
- CVSS:
- 7.5
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.7
- Disclosed:
- Feb 8, 2024
CVE-2024-0842 on NVD →
Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.2.4
unknown
[en] The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.3 via the node_id parameter in the backuply_get_jstree function. This makes it possible for attackers with administrator privileges or higher to read the contents of...
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
- Disclosed:
- Jan 27, 2024
CVE-2024-0697 on NVD →
Backuply – Backup, Restore, Migrate and Clone <= 1.2.3 - Authenticated (Administrator+) Directory Traversal
medium
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.3 via the node_id parameter in the backuply_get_jstree function. This makes it possible for attackers with administrator privileges or higher to read the contents of arbi...
- CVSS:
- 6.5
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Jan 26, 2024
CVE-2024-0697 on NVD →
Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.4.9
unknown
- Affected:
- up to 1.4.9
- Fixed in:
- 1.4.9
CVE-2025-10307 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database