BackItUp <= 2.1.0 - Missing Authorization
medium
The BackItUp plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.1.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.1.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 21, 2026
CVE-2025-68039 on NVD →
Backup and Restore Wordpress <= 1.50 - Cross-Site Request Forgery to Backup Trigger
medium
The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.50. This is due to missing or incorrect nonce validation on the ajax_queue_manual_backup() function. This makes it possible for unauthenticated attackers to trigger b...
- CVSS:
- 6.5
- Affected:
- up to 1.50
- Fixed in:
- 2.0.0
- Disclosed:
- Aug 12, 2024
CVE-2024-43269 on NVD →
Backup and Restore WordPress <= 1.50 - Missing Authorization
medium
The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.50. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.50
- Fixed in:
- 2.0.0
- Disclosed:
- Aug 12, 2024
CVE-2024-43270 on NVD →
Backup and Restore WordPress <= 1.50 - Missing Authorization
medium
The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.50. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized ac...
- CVSS:
- 4.3
- Affected:
- up to 1.50
- Fixed in:
- 2.0.0
- Disclosed:
- Aug 12, 2024
CVE-2024-43268 on NVD →
Backup and Restore WordPress WordPress <= 1.45 - Unauthenticated Information Exposure via Log Files
medium
The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.45 via log files. This makes it possible for unauthenticated attackers to extract potentially sensitive information via log files.
- CVSS:
- 5.3
- Affected:
- up to 1.45
- Fixed in:
- 1.50
- Disclosed:
- Mar 5, 2024
CVE-2023-7232 on NVD →
Backup and Restore WordPress – Backup Plugin <= 1.9 - Authorization Bypass
medium
The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to trigger manual bac...
- CVSS:
- 6.5
- Affected:
- up to 1.9
- Fixed in:
- 1.9.1
- Disclosed:
- Dec 4, 2014
Backup and Restore WordPress – Backup Plugin <= 1.9 - Sensitive Information Disclosure
high
The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.9 via the 'wp-backitup\lib\includes\job_backup.php' file. This can allow unauthenticated attackers to extract sensitive data including otherwise restricted backup files.
- CVSS:
- 7.5
- Affected:
- up to 1.9
- Fixed in:
- 1.9.1
- Disclosed:
- Jul 16, 2014
CVE-2014-9012 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database