Bears Backup <= 2.0.0 - Unauthenticated Remote Code Execution
criticalThe Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0. This is due to the bbackup_ajax_handle() function not having a capability check, nor validating user supplied input passed directly to call_user_func(). This makes it possible for unauthenticated at...
- CVSS:
- 9.8
- Affected:
- up to 2.0.0
- Fixed in:
- 2.1.0
- Disclosed:
- Jul 16, 2025