plugin

Bears Backup Vulnerabilities

1 known security issue reported for the Bears Backup WordPress plugin. Most recent disclosed Jul 16, 2025.

1 critical

Running Bears Backup on your site? Check whether your installed version is affected.

Scan your site free

Bears Backup <= 2.0.0 - Unauthenticated Remote Code Execution

critical

The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0. This is due to the bbackup_ajax_handle() function not having a capability check, nor validating user supplied input passed directly to call_user_func(). This makes it possible for unauthenticated at...

CVSS:
9.8
Affected:
up to 2.0.0
Fixed in:
2.1.0
Disclosed:
Jul 16, 2025

CVE-2025-5396 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database