plugin

Simple Backup Vulnerabilities

7 known security issues reported for the Simple Backup WordPress plugin. Most recent disclosed Jun 15, 2026.

2 high

Running Simple Backup on your site? Check whether your installed version is affected.

Scan your site free

Simple-Backup <= 2.7.11 - Unauthenticated Arbitrary File Download

high

The Simple Backup plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.7.11. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
7.5
Affected:
up to 2.7.11
Fix:
No patched version reported
Disclosed:
Jun 15, 2026

CVE-2016-20076 on NVD →

Simple Backup [simple-backup] < 2.7.11 (closed)

unknown

[en] The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-confi...

Affected:
up to 2.7.11
Fixed in:
2.7.11
Disclosed:
Jul 19, 2025

CVE-2015-10134 on NVD →

Simple Backup [simple-backup] < 2.7.12 (closed)

unknown

Simple Backup plugin is prone to multiple vulnerabilities, such as arbitrary file deletion and file download vulnerabilities. Because of these issues, an attacker can download remote files from the webserver delete arbitrary files without any authentication and permission. Update the plugin.

Affected:
up to 2.7.12
Fixed in:
2.7.12
Disclosed:
Jun 6, 2016

Simple Backup <= 2.7.10 - Arbitrary File Download via Path Traversal

high

The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-config.php...

CVSS:
7.5
Affected:
up to 2.7.11
Fixed in:
2.7.11
Disclosed:
May 19, 2015

CVE-2015-10134 on NVD →

Simple Backup [simple-backup] < 2.7.11 (closed)

unknown

This plugin is prone to an arbitrary file download vulnerability. Update the plugin.

Affected:
up to 2.7.11
Fixed in:
2.7.11
Disclosed:
May 19, 2015

Simple Backup [simple-backup] < 2.7.11

unknown

The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-config.php...

Affected:
up to 2.7.11
Fixed in:
2.7.11
Disclosed:
May 19, 2015

Simple Backup [simple-backup] < 2.7.11 (closed)

unknown

The simple-backup WordPress plugin was affected by an Arbitrary File Download security vulnerability.

Affected:
up to 2.7.11
Fixed in:
2.7.11

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database