Simple-Backup <= 2.7.11 - Unauthenticated Arbitrary File Download
high
The Simple Backup plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.7.11. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 2.7.11
- Fix:
- No patched version reported
- Disclosed:
- Jun 15, 2026
CVE-2016-20076 on NVD →
Simple Backup [simple-backup] < 2.7.11 (closed)
unknown
[en] The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-confi...
- Affected:
- up to 2.7.11
- Fixed in:
- 2.7.11
- Disclosed:
- Jul 19, 2025
CVE-2015-10134 on NVD →
Simple Backup [simple-backup] < 2.7.12 (closed)
unknown
Simple Backup plugin is prone to multiple vulnerabilities, such as arbitrary file deletion and file download vulnerabilities. Because of these issues, an attacker can download remote files from the webserver delete arbitrary files without any authentication and permission.
Update the plugin.
- Affected:
- up to 2.7.12
- Fixed in:
- 2.7.12
- Disclosed:
- Jun 6, 2016
Simple Backup <= 2.7.10 - Arbitrary File Download via Path Traversal
high
The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-config.php...
- CVSS:
- 7.5
- Affected:
- up to 2.7.11
- Fixed in:
- 2.7.11
- Disclosed:
- May 19, 2015
CVE-2015-10134 on NVD →
Simple Backup [simple-backup] < 2.7.11 (closed)
unknown
This plugin is prone to an arbitrary file download vulnerability.
Update the plugin.
- Affected:
- up to 2.7.11
- Fixed in:
- 2.7.11
- Disclosed:
- May 19, 2015
Simple Backup [simple-backup] < 2.7.11
unknown
The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-config.php...
- Affected:
- up to 2.7.11
- Fixed in:
- 2.7.11
- Disclosed:
- May 19, 2015
Simple Backup [simple-backup] < 2.7.11 (closed)
unknown
The simple-backup WordPress plugin was affected by an Arbitrary File Download security vulnerability.
- Affected:
- up to 2.7.11
- Fixed in:
- 2.7.11
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database