Database Backup for WordPress <= 2.5.2 - Missing Authorization to Unauthenticated Arbitrary File Read and Deletion
high
The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter. This...
- CVSS:
- 8.1
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- May 13, 2026
CVE-2026-4030 on NVD →
Database Backup for WordPress <= 2.5.2 - Missing Authorization to Unauthenticated Database Backup Interception
high
The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database backups are written. This makes it possible for unauthenticated attack...
- CVSS:
- 7.5
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- May 13, 2026
CVE-2026-4031 on NVD →
Database Backup for WordPress <= 2.5.2 - Missing Authorization to Unauthenticated Database Export
high
The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check. This makes it possible for unauthenticated attackers to export database tables,...
- CVSS:
- 7.5
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- May 13, 2026
CVE-2026-4029 on NVD →
Database Backup for WordPress [wp-db-backup] < 2.5.2
unknown
[en] The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. This could lead to cases where attackers can send backup notification emails to themselves, whic...
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
- Disclosed:
- Jun 6, 2022
CVE-2022-1577 on NVD →
Database Backup for WordPress <= 2.5.1 - Cross-Site Request Forgery to Settings Update
high
The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. This could lead to cases where attackers can send backup notification emails to themselves, which con...
- CVSS:
- 8.8
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
- Disclosed:
- May 11, 2022
CVE-2022-1577 on NVD →
Database Backup for WordPress [wp-db-backup] < 2.5.1
unknown
[en] The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.1
- Disclosed:
- Feb 21, 2022
CVE-2022-0255 on NVD →
Database Backup for WordPress <= 2.5 - Admin+ SQL Injection
high
The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue
- CVSS:
- 7.2
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.1
- Disclosed:
- Jan 24, 2022
CVE-2022-0255 on NVD →
Database Backup for WordPress [wp-db-backup] < 2.4
unknown
[en] The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Jun 1, 2021
CVE-2021-24322 on NVD →
Database Backup for WordPress <= 2.3.3 - Authenticated Stored Cross-Site Scripting via backup_receipient Parameter
medium
The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.
- CVSS:
- 5.4
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- May 16, 2021
CVE-2021-24322 on NVD →
Database Backup for WordPress [wp-db-backup] < 2.4
unknown
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in Database Backup for WordPress plugin (versions <= 2.3.3).
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Apr 22, 2021
Database Backup for WordPress [wp-db-backup] < 2.3.0
unknown
[en] The wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read backup archives via a brute-force attack.
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.0
- Disclosed:
- Oct 5, 2018
CVE-2014-10076 on NVD →
Database Backup for WordPress <= 2.2.4 - Missing Authorization
high
The wp-db-backup plugin up to 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read backup archives via a brute-force attack.
- CVSS:
- 7.5
- Affected:
- up to 2.2.4
- Fixed in:
- 2.3.0
- Disclosed:
- Nov 2, 2014
CVE-2014-10076 on NVD →
Database Backup for WordPress [wp-db-backup] <= 1.7
unknown
[en] Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plugin for WordPress 1.7 and earlier allows remote authenticated users with administrative privileges to read arbitrary files via a .. (dot dot) in the backup parameter to edit.php.
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Aug 17, 2006
CVE-2006-4208 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database