BackWPup <= 5.7.4 - Unauthenticated Stored Cross-Site Scripting
high
The BackWPup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an i...
- CVSS:
- 7.2
- Affected:
- up to 5.7.4
- Fixed in:
- 5.7.5
- Disclosed:
- Jul 27, 2026
CVE-2026-65443 on NVD →
BackWPup <= 5.6.6 - Authenticated (Administrator+) Local File Inclusion via 'block_name' Parameter
high
The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/backwpup/v1/getblock` REST endpoint in all versions up to, and including, 5.6.6 due to a non-recursive `str_replace()` sanitization of path traversal sequences. This makes it possible for authenticate...
- CVSS:
- 7.2
- Affected:
- up to 5.6.6
- Fixed in:
- 5.6.7
- Disclosed:
- Apr 13, 2026
CVE-2026-6227 on NVD →
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 5.6.3
unknown
[en] The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the save_site_option() function in all versions up to, and including, 5.6.2. This makes it possible for authenticated a...
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.3
- Disclosed:
- Feb 19, 2026
CVE-2025-15041 on NVD →
BackWPup 5.0.0 - 5.6.2 - Authenticated (BackWPup Helper+) Privilege Escalation via Arbitrary Options Update
high
The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the save_site_option() function in all versions 5.0.0 to 5.6.2. This makes it possible for authenticated attackers, with lev...
- CVSS:
- 7.2
- Affected:
- 5.0.0 – 5.6.2
- Fixed in:
- 5.6.3
- Disclosed:
- Feb 18, 2026
CVE-2025-15041 on NVD →
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 5.5.1
unknown
[en] The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'backwpup_working' AJAX action in all versions up to, and including, 5.5.0. This makes it possible for authenticated attackers, with Subscriber-level access an...
- Affected:
- up to 5.5.1
- Fixed in:
- 5.5.1
- Disclosed:
- Oct 25, 2025
CVE-2025-10579 on NVD →
BackWPup 5 - 5.5.0 - Missing Authorization to Sensitive Information Exposure
medium
The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'backwpup_working' AJAX action in versions 5 through 5.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve...
- CVSS:
- 5.3
- Affected:
- 5 – 5.5.0
- Fixed in:
- 5.5.1
- Disclosed:
- Oct 24, 2025
CVE-2025-10579 on NVD →
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 4.0.2
unknown
[en] The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the job-specific backup folder. This allows authenticated attackers to store backups in arbitrary folders on the server provided they can be written to by the server. Additionally, default settings wi...
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- Aug 17, 2024
CVE-2023-5505 on NVD →
BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal
medium
The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the job-specific backup folder. This allows authenticated attackers to store backups in arbitrary folders on the server provided they can be written to by the server. Additionally, default settings will pl...
- CVSS:
- 6.8
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- Aug 16, 2024
CVE-2023-5505 on NVD →
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 4.0.4
unknown
[en] The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.4
- Disclosed:
- Apr 8, 2024
CVE-2023-7164 on NVD →
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 4.0.3
unknown
[en] The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. This makes it possible for authenticated attackers, with administrator-level ac...
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.3
- Disclosed:
- Feb 24, 2024
CVE-2023-5775 on NVD →
BackWPup <= 4.0.2 - Plaintext Storage of Backup Destination Password
low
The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. This makes it possible for authenticated attackers, with administrator-level access,...
- CVSS:
- 2.2
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.3
- Disclosed:
- Feb 23, 2024
CVE-2023-5775 on NVD →
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 4.0.2
unknown
[en] The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the Log File Folder. This allows authenticated attackers to store backups in arbitrary folders on the server provided they can be written to by the server. Additionally, default settings will place an...
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- Jan 11, 2024
CVE-2023-5504 on NVD →
BackWPup <= 4.0.3 - Sensitive Information Exposure
high
The BackWPup – WordPress Backup Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 7.5
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.4
- Disclosed:
- Dec 18, 2023
CVE-2023-7164 on NVD →
BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal
high
The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the Log File Folder. This allows authenticated attackers to store backups in arbitrary folders on the server provided they can be written to by the server. Additionally, default settings will place an inde...
- CVSS:
- 8.7
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- Nov 22, 2023
CVE-2023-5504 on NVD →
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 3.4.2
unknown
Unrestricted Backup File Download vulnerability found by Larry W. Cashdollar in WordPress BackWPup plugin (versions <=3.4.1). Backup files are stored insecurely and could be discovered by Google dork and exploited further even for brute-forcing.
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.2
- Disclosed:
- Sep 28, 2017
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 3.4.2
unknown
[en] Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.2
- Disclosed:
- Sep 27, 2017
CVE-2017-2551 on NVD →
BackWPup <= 3.4.1 - Unauthenticated Backup Download
high
Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.
- CVSS:
- 7.5
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.2
- Disclosed:
- Sep 8, 2017
CVE-2017-2551 on NVD →
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 3.3
unknown
In version 3.2.5, WordPress BackWPup plugin, some variables are echoed without escaping.
Update the plugin.
- Affected:
- up to 3.3
- Fixed in:
- 3.3
- Disclosed:
- Mar 22, 2017
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 1.7.2
unknown
This plugin is prone to remote and local code execution vulnerability.
Update the plugin.
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- May 15, 2015
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 3.0.13
unknown
[en] Cross-site scripting (XSS) vulnerability in the BackWPup plugin before 3.0.13 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter to wp-admin/admin.php.
- Affected:
- up to 3.0.13
- Fixed in:
- 3.0.13
- Disclosed:
- Sep 26, 2013
CVE-2013-4626 on NVD →
BackWPup < 3.0.13 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the BackWPup plugin before 3.0.13 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter to wp-admin/admin.php.
- CVSS:
- 6.1
- Affected:
- up to 3.0.13
- Fixed in:
- 3.0.13
- Disclosed:
- Aug 21, 2013
CVE-2013-4626 on NVD →
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 1.7.2
unknown
[en] PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter.
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Oct 8, 2012
CVE-2011-4342 on NVD →
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 1.4.1
unknown
[en] Multiple directory traversal vulnerabilities in the BackWPup plugin before 1.4.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the wpabs parameter to (1) app/options-view_log-iframe.php or (2) app/options-runnow-iframe.php.
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
- Disclosed:
- Oct 8, 2012
CVE-2011-5208 on NVD →
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 2.1.5
unknown
BackWPup is prone to a code execution vulnerability that can be exploited to execute local or remote code on the web server. It allows an attacker to specify FTP resources as input by using a lack of data validation on the BackWPUpJobTemp POST parameter of job/wp_export_generate.php.
Upgrade to BackWPUp 2.1.5 of above.
- Affected:
- up to 2.1.5
- Fixed in:
- 2.1.5
- Disclosed:
- Oct 17, 2011
BackWPup <= 1.7.1 - Remote File Inclusion
critical
PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Mar 28, 2011
CVE-2011-4342 on NVD →
BackWPup – WordPress Backup Plugin < 1.4.1 - Directory Traversal
high
Multiple directory traversal vulnerabilities in the BackWPup plugin before 1.4.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the wpabs parameter to (1) app/options-view_log-iframe.php or (2) app/options-runnow-iframe.php.
- CVSS:
- 7.5
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
- Disclosed:
- Mar 2, 2011
CVE-2011-5208 on NVD →
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 1.5
unknown
Because of these multiple information-disclosure vulnerabilities attackers can try to retrieve the contents of an arbitrary file. Other attacks are also possible.
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Feb 28, 2011
BackWPup – WordPress Backup & Restore Plugin [backwpup] < 2.1.5
unknown
The BackWPup – WordPress Backup Plugin WordPress plugin was affected by a Code Execution security vulnerability.
- Affected:
- up to 2.1.5
- Fixed in:
- 2.1.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database