plugin

Backupwordpress Vulnerabilities

7 known security issues reported for the Backupwordpress WordPress plugin. Most recent disclosed Apr 27, 2024.

1 critical 1 medium 1 low

Running Backupwordpress on your site? Check whether your installed version is affected.

Scan your site free

BackUpWordPress [backupwordpress] < 3.14

unknown

[en] The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to traverse directories outside of the context in which t...

Affected:
up to 3.14
Fixed in:
3.14
Disclosed:
Apr 27, 2024

CVE-2024-3034 on NVD →

BackUpWordPress <= 3.13 - Authenticated (Admin+) Directory Traversal

low

The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to traverse directories outside of the context in which the pl...

CVSS:
2.7
Affected:
up to 3.13
Fixed in:
3.14
Disclosed:
Apr 26, 2024

CVE-2024-3034 on NVD →

BackUpWordPress [backupwordpress] < 3.13

unknown

[en] The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissio...

Affected:
up to 3.13
Fixed in:
3.13
Disclosed:
Mar 7, 2023

CVE-2022-4931 on NVD →

BackupWordPress <= 3.12 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure

medium

The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions an...

CVSS:
4.3
Affected:
3.12 – 3.12
Fixed in:
3.13
Disclosed:
Feb 23, 2022

CVE-2022-4931 on NVD →

BackUpWordPress [backupwordpress] < 0.4.3

unknown

[en] Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow remote attackers to execute arbitrary PHP code via a URL in the bkpwp_plugin_path parameter to (1) plugins/BackUp/Archive.php; and (2) Predicate.php, (3) Writer.php, (4) Reader.php, and other uns...

Affected:
up to 0.4.3
Fixed in:
0.4.3
Disclosed:
Nov 3, 2007

CVE-2007-5800 on NVD →

BackUpWordPress <= 0.4.2b - Remote File Inclusion

critical

Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow remote attackers to execute arbitrary PHP code via a URL in the bkpwp_plugin_path parameter to (1) plugins/BackUp/Archive.php; and (2) Predicate.php, (3) Writer.php, (4) Reader.php, and other unspecif...

CVSS:
9.8
Affected:
up to 0.4.3
Fixed in:
0.4.3
Disclosed:
Nov 1, 2007

CVE-2007-5800 on NVD →

BackUpWordPress [backupwordpress] < 0.4.3

unknown

The BackUpWordPress WordPress plugin was affected by a RFI security vulnerability.

Affected:
up to 0.4.3
Fixed in:
0.4.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database