plugin

Wp Backitup Vulnerabilities

7 known security issues reported for the Wp Backitup WordPress plugin. Most recent disclosed Jan 21, 2026.

1 high 6 medium

Running Wp Backitup on your site? Check whether your installed version is affected.

Scan your site free

BackItUp <= 2.1.0 - Missing Authorization

medium

The BackItUp plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.1.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.1.0
Fix:
No patched version reported
Disclosed:
Jan 21, 2026

CVE-2025-68039 on NVD →

Backup and Restore Wordpress <= 1.50 - Cross-Site Request Forgery to Backup Trigger

medium

The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.50. This is due to missing or incorrect nonce validation on the ajax_queue_manual_backup() function. This makes it possible for unauthenticated attackers to trigger b...

CVSS:
6.5
Affected:
up to 1.50
Fixed in:
2.0.0
Disclosed:
Aug 12, 2024

CVE-2024-43269 on NVD →

Backup and Restore WordPress <= 1.50 - Missing Authorization

medium

The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.50. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.50
Fixed in:
2.0.0
Disclosed:
Aug 12, 2024

CVE-2024-43270 on NVD →

Backup and Restore WordPress <= 1.50 - Missing Authorization

medium

The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.50. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized ac...

CVSS:
4.3
Affected:
up to 1.50
Fixed in:
2.0.0
Disclosed:
Aug 12, 2024

CVE-2024-43268 on NVD →

Backup and Restore WordPress WordPress <= 1.45 - Unauthenticated Information Exposure via Log Files

medium

The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.45 via log files. This makes it possible for unauthenticated attackers to extract potentially sensitive information via log files.

CVSS:
5.3
Affected:
up to 1.45
Fixed in:
1.50
Disclosed:
Mar 5, 2024

CVE-2023-7232 on NVD →

Backup and Restore WordPress – Backup Plugin <= 1.9 - Authorization Bypass

medium

The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to trigger manual bac...

CVSS:
6.5
Affected:
up to 1.9
Fixed in:
1.9.1
Disclosed:
Dec 4, 2014

Backup and Restore WordPress – Backup Plugin <= 1.9 - Sensitive Information Disclosure

high

The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.9 via the 'wp-backitup\lib\includes\job_backup.php' file. This can allow unauthenticated attackers to extract sensitive data including otherwise restricted backup files.

CVSS:
7.5
Affected:
up to 1.9
Fixed in:
1.9.1
Disclosed:
Jul 16, 2014

CVE-2014-9012 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database