Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.12 - Unauthenticated SQL Injection
high
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.3.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible f...
- CVSS:
- 7.5
- Affected:
- up to 2.3.12
- Fix:
- No patched version reported
- Disclosed:
- Aug 10, 2026
CVE-2026-66472 on NVD →
Everest Backup <= 2.3.9 - Cross-Site Request Forgery
medium
The Everest Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.9. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can tr...
- CVSS:
- 4.3
- Affected:
- up to 2.3.9
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-62992 on NVD →
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin [everest-backup] <= 2.3.9 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Everest themes Everest Backup allows Path Traversal.This issue affects Everest Backup: from n/a through 2.3.9.
- Affected:
- up to 2.3.9
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-62992 on NVD →
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin [everest-backup] < 2.3.9 (closed)
unknown
[en] The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the process_status_unlink() function in all versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to d...
- Affected:
- up to 2.3.9
- Fixed in:
- 2.3.9
- Disclosed:
- Dec 3, 2025
CVE-2025-10304 on NVD →
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 - Missing Authorization to Unauthenticated Backup Failure
medium
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the process_status_unlink() function in all versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to delete...
- CVSS:
- 5.3
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.9
- Disclosed:
- Dec 2, 2025
CVE-2025-10304 on NVD →
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin [everest-backup] <= 2.3.8 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in everestthemes Everest Backup everest-backup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Everest Backup: from n/a through <= 2.3.8.
- Affected:
- up to 2.3.8
- Fix:
- No patched version reported
- Disclosed:
- Oct 27, 2025
CVE-2025-62946 on NVD →
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin [everest-backup] < 2.3.6 (closed)
unknown
[en] The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'everest_process_status' AJAX action in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated at...
- Affected:
- up to 2.3.6
- Fixed in:
- 2.3.6
- Disclosed:
- Oct 11, 2025
CVE-2025-11380 on NVD →
Everest Backup <= 2.3.5 - Missing Authorization to Unauthenticated Information Exposure
medium
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'everest_process_status' AJAX action in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated attacke...
- CVSS:
- 5.9
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.6
- Disclosed:
- Oct 10, 2025
CVE-2025-11380 on NVD →
Everest Backup <= 2.3.8 - Missing Authorization
medium
The Everest Backup plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.9
- Disclosed:
- Oct 10, 2025
CVE-2025-62946 on NVD →
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin [everest-backup] < 2.3.4 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup allows Cross Site Request Forgery. This issue affects Everest Backup: from n/a through 2.3.3.
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Jun 6, 2025
CVE-2025-49238 on NVD →
Everest Backup <= 2.3.3 - Cross-Site Request Forgery
medium
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perfo...
- CVSS:
- 4.3
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.4
- Disclosed:
- Jun 5, 2025
CVE-2025-49238 on NVD →
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.2.13 - Sensitive Invormation Disclosure via procstat Log
high
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.13 via the exposed process stats file during the backup process. This makes it possible for unauthenticated attackers to obtain...
- CVSS:
- 7.5
- Affected:
- up to 2.2.13
- Fixed in:
- 2.2.14
- Disclosed:
- Nov 5, 2024
CVE-2024-10028 on NVD →
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin [everest-backup] < 2.2.14 (closed)
unknown
[en] The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.13 via the exposed process stats file during the backup process. This makes it possible for unauthenticated attackers to ob...
- Affected:
- up to 2.2.14
- Fixed in:
- 2.2.14
- Disclosed:
- Nov 5, 2024
CVE-2024-10028 on NVD →
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin [everest-backup] < 2.2.5 (closed)
unknown
[en] The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Apr 15, 2024
CVE-2023-7201 on NVD →
Everest Backup <= 2.2.4 - Authenticated (Admin+) Arbitrary File Upload
high
The Everest Backup plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the backup file upload functionality in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary file...
- CVSS:
- 7.2
- Affected:
- up to 2.2.4
- Fixed in:
- 2.2.5
- Disclosed:
- Mar 25, 2024
CVE-2023-7201 on NVD →
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin [everest-backup] < 2.2.0 (closed)
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Everestthemes Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin.This issue affects Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin: from n/a through 2.1.9.
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- Dec 31, 2023
CVE-2023-52185 on NVD →
Everest Backup <= 2.1.9 - Sensitive Information Exposure via Log File
high
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 2.2.0 (exclusive) via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data including the locations...
- CVSS:
- 7.5
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- Dec 29, 2023
CVE-2023-52185 on NVD →
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin [everest-backup] < 1.0.8 (closed)
unknown
The Everest Backup plugin for WordPress is vulnerable to backup export disclosure in versions up to, and including, 1.0.7. This is due to insufficient access controls on the everest_backup_get_ajax_response() function. This makes it possible for authenticated attackers to reveal sensitive information about back-ups cre...
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.8
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database