plugin

Backwpup Vulnerabilities

28 known security issues reported for the Backwpup WordPress plugin. Most recent disclosed Jul 27, 2026.

1 critical 7 high 3 medium 1 low

Running Backwpup on your site? Check whether your installed version is affected.

Scan your site free

BackWPup <= 5.7.4 - Unauthenticated Stored Cross-Site Scripting

high

The BackWPup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an i...

CVSS:
7.2
Affected:
up to 5.7.4
Fixed in:
5.7.5
Disclosed:
Jul 27, 2026

CVE-2026-65443 on NVD →

BackWPup <= 5.6.6 - Authenticated (Administrator+) Local File Inclusion via 'block_name' Parameter

high

The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/backwpup/v1/getblock` REST endpoint in all versions up to, and including, 5.6.6 due to a non-recursive `str_replace()` sanitization of path traversal sequences. This makes it possible for authenticate...

CVSS:
7.2
Affected:
up to 5.6.6
Fixed in:
5.6.7
Disclosed:
Apr 13, 2026

CVE-2026-6227 on NVD →

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 5.6.3

unknown

[en] The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the save_site_option() function in all versions up to, and including, 5.6.2. This makes it possible for authenticated a...

Affected:
up to 5.6.3
Fixed in:
5.6.3
Disclosed:
Feb 19, 2026

CVE-2025-15041 on NVD →

BackWPup 5.0.0 - 5.6.2 - Authenticated (BackWPup Helper+) Privilege Escalation via Arbitrary Options Update

high

The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the save_site_option() function in all versions 5.0.0 to 5.6.2. This makes it possible for authenticated attackers, with lev...

CVSS:
7.2
Affected:
5.0.0 – 5.6.2
Fixed in:
5.6.3
Disclosed:
Feb 18, 2026

CVE-2025-15041 on NVD →

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 5.5.1

unknown

[en] The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'backwpup_working' AJAX action in all versions up to, and including, 5.5.0. This makes it possible for authenticated attackers, with Subscriber-level access an...

Affected:
up to 5.5.1
Fixed in:
5.5.1
Disclosed:
Oct 25, 2025

CVE-2025-10579 on NVD →

BackWPup 5 - 5.5.0 - Missing Authorization to Sensitive Information Exposure

medium

The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'backwpup_working' AJAX action in versions 5 through 5.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve...

CVSS:
5.3
Affected:
5 – 5.5.0
Fixed in:
5.5.1
Disclosed:
Oct 24, 2025

CVE-2025-10579 on NVD →

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 4.0.2

unknown

[en] The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the job-specific backup folder. This allows authenticated attackers to store backups in arbitrary folders on the server provided they can be written to by the server. Additionally, default settings wi...

Affected:
up to 4.0.2
Fixed in:
4.0.2
Disclosed:
Aug 17, 2024

CVE-2023-5505 on NVD →

BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal

medium

The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the job-specific backup folder. This allows authenticated attackers to store backups in arbitrary folders on the server provided they can be written to by the server. Additionally, default settings will pl...

CVSS:
6.8
Affected:
up to 4.0.1
Fixed in:
4.0.2
Disclosed:
Aug 16, 2024

CVE-2023-5505 on NVD →

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 4.0.4

unknown

[en] The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.

Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Apr 8, 2024

CVE-2023-7164 on NVD →

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 4.0.3

unknown

[en] The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. This makes it possible for authenticated attackers, with administrator-level ac...

Affected:
up to 4.0.3
Fixed in:
4.0.3
Disclosed:
Feb 24, 2024

CVE-2023-5775 on NVD →

BackWPup <= 4.0.2 - Plaintext Storage of Backup Destination Password

low

The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. This makes it possible for authenticated attackers, with administrator-level access,...

CVSS:
2.2
Affected:
up to 4.0.2
Fixed in:
4.0.3
Disclosed:
Feb 23, 2024

CVE-2023-5775 on NVD →

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 4.0.2

unknown

[en] The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the Log File Folder. This allows authenticated attackers to store backups in arbitrary folders on the server provided they can be written to by the server. Additionally, default settings will place an...

Affected:
up to 4.0.2
Fixed in:
4.0.2
Disclosed:
Jan 11, 2024

CVE-2023-5504 on NVD →

BackWPup <= 4.0.3 - Sensitive Information Exposure

high

The BackWPup – WordPress Backup Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
7.5
Affected:
up to 4.0.3
Fixed in:
4.0.4
Disclosed:
Dec 18, 2023

CVE-2023-7164 on NVD →

BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal

high

The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the Log File Folder. This allows authenticated attackers to store backups in arbitrary folders on the server provided they can be written to by the server. Additionally, default settings will place an inde...

CVSS:
8.7
Affected:
up to 4.0.1
Fixed in:
4.0.2
Disclosed:
Nov 22, 2023

CVE-2023-5504 on NVD →

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 3.4.2

unknown

Unrestricted Backup File Download vulnerability found by Larry W. Cashdollar in WordPress BackWPup plugin (versions <=3.4.1). Backup files are stored insecurely and could be discovered by Google dork and exploited further even for brute-forcing.

Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Sep 28, 2017

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 3.4.2

unknown

[en] Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.

Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Sep 27, 2017

CVE-2017-2551 on NVD →

BackWPup <= 3.4.1 - Unauthenticated Backup Download

high

Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.

CVSS:
7.5
Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Sep 8, 2017

CVE-2017-2551 on NVD →

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 3.3

unknown

In version 3.2.5, WordPress BackWPup plugin, some variables are echoed without escaping. Update the plugin.

Affected:
up to 3.3
Fixed in:
3.3
Disclosed:
Mar 22, 2017

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 1.7.2

unknown

This plugin is prone to remote and local code execution vulnerability. Update the plugin.

Affected:
up to 1.7.2
Fixed in:
1.7.2
Disclosed:
May 15, 2015

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 3.0.13

unknown

[en] Cross-site scripting (XSS) vulnerability in the BackWPup plugin before 3.0.13 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter to wp-admin/admin.php.

Affected:
up to 3.0.13
Fixed in:
3.0.13
Disclosed:
Sep 26, 2013

CVE-2013-4626 on NVD →

BackWPup < 3.0.13 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the BackWPup plugin before 3.0.13 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter to wp-admin/admin.php.

CVSS:
6.1
Affected:
up to 3.0.13
Fixed in:
3.0.13
Disclosed:
Aug 21, 2013

CVE-2013-4626 on NVD →

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 1.7.2

unknown

[en] PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter.

Affected:
up to 1.7.2
Fixed in:
1.7.2
Disclosed:
Oct 8, 2012

CVE-2011-4342 on NVD →

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 1.4.1

unknown

[en] Multiple directory traversal vulnerabilities in the BackWPup plugin before 1.4.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the wpabs parameter to (1) app/options-view_log-iframe.php or (2) app/options-runnow-iframe.php.

Affected:
up to 1.4.1
Fixed in:
1.4.1
Disclosed:
Oct 8, 2012

CVE-2011-5208 on NVD →

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 2.1.5

unknown

BackWPup is prone to a code execution vulnerability that can be exploited to execute local or remote code on the web server. It allows an attacker to specify FTP resources as input by using a lack of data validation on the BackWPUpJobTemp POST parameter of job/wp_export_generate.php. Upgrade to BackWPUp 2.1.5 of above.

Affected:
up to 2.1.5
Fixed in:
2.1.5
Disclosed:
Oct 17, 2011

BackWPup <= 1.7.1 - Remote File Inclusion

critical

PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter.

CVSS:
9.8
Affected:
up to 1.7.1
Fixed in:
1.7.2
Disclosed:
Mar 28, 2011

CVE-2011-4342 on NVD →

BackWPup – WordPress Backup Plugin < 1.4.1 - Directory Traversal

high

Multiple directory traversal vulnerabilities in the BackWPup plugin before 1.4.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the wpabs parameter to (1) app/options-view_log-iframe.php or (2) app/options-runnow-iframe.php.

CVSS:
7.5
Affected:
up to 1.4.1
Fixed in:
1.4.1
Disclosed:
Mar 2, 2011

CVE-2011-5208 on NVD →

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 1.5

unknown

Because of these multiple information-disclosure vulnerabilities attackers can try to retrieve the contents of an arbitrary file. Other attacks are also possible.

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Feb 28, 2011

BackWPup – WordPress Backup &amp; Restore Plugin [backwpup] < 2.1.5

unknown

The BackWPup &ndash; WordPress Backup Plugin WordPress plugin was affected by a Code Execution security vulnerability.

Affected:
up to 2.1.5
Fixed in:
2.1.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database