BackUpWordPress [backupwordpress] < 3.14
unknown
[en] The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to traverse directories outside of the context in which t...
- Affected:
- up to 3.14
- Fixed in:
- 3.14
- Disclosed:
- Apr 27, 2024
CVE-2024-3034 on NVD →
BackUpWordPress <= 3.13 - Authenticated (Admin+) Directory Traversal
low
The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to traverse directories outside of the context in which the pl...
- CVSS:
- 2.7
- Affected:
- up to 3.13
- Fixed in:
- 3.14
- Disclosed:
- Apr 26, 2024
CVE-2024-3034 on NVD →
BackUpWordPress [backupwordpress] < 3.13
unknown
[en] The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissio...
- Affected:
- up to 3.13
- Fixed in:
- 3.13
- Disclosed:
- Mar 7, 2023
CVE-2022-4931 on NVD →
BackupWordPress <= 3.12 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure
medium
The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions an...
- CVSS:
- 4.3
- Affected:
- 3.12 – 3.12
- Fixed in:
- 3.13
- Disclosed:
- Feb 23, 2022
CVE-2022-4931 on NVD →
BackUpWordPress [backupwordpress] < 0.4.3
unknown
[en] Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow remote attackers to execute arbitrary PHP code via a URL in the bkpwp_plugin_path parameter to (1) plugins/BackUp/Archive.php; and (2) Predicate.php, (3) Writer.php, (4) Reader.php, and other uns...
- Affected:
- up to 0.4.3
- Fixed in:
- 0.4.3
- Disclosed:
- Nov 3, 2007
CVE-2007-5800 on NVD →
BackUpWordPress <= 0.4.2b - Remote File Inclusion
critical
Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow remote attackers to execute arbitrary PHP code via a URL in the bkpwp_plugin_path parameter to (1) plugins/BackUp/Archive.php; and (2) Predicate.php, (3) Writer.php, (4) Reader.php, and other unspecif...
- CVSS:
- 9.8
- Affected:
- up to 0.4.3
- Fixed in:
- 0.4.3
- Disclosed:
- Nov 1, 2007
CVE-2007-5800 on NVD →
BackUpWordPress [backupwordpress] < 0.4.3
unknown
The BackUpWordPress WordPress plugin was affected by a RFI security vulnerability.
- Affected:
- up to 0.4.3
- Fixed in:
- 0.4.3
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database