plugin

Wp Db Backup Vulnerabilities

13 known security issues reported for the Wp Db Backup WordPress plugin. Most recent disclosed May 13, 2026.

6 high 1 medium

Running Wp Db Backup on your site? Check whether your installed version is affected.

Scan your site free

Database Backup for WordPress <= 2.5.2 - Missing Authorization to Unauthenticated Arbitrary File Read and Deletion

high

The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter. This...

CVSS:
8.1
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
May 13, 2026

CVE-2026-4030 on NVD →

Database Backup for WordPress <= 2.5.2 - Missing Authorization to Unauthenticated Database Backup Interception

high

The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database backups are written. This makes it possible for unauthenticated attack...

CVSS:
7.5
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
May 13, 2026

CVE-2026-4031 on NVD →

Database Backup for WordPress <= 2.5.2 - Missing Authorization to Unauthenticated Database Export

high

The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check. This makes it possible for unauthenticated attackers to export database tables,...

CVSS:
7.5
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
May 13, 2026

CVE-2026-4029 on NVD →

Database Backup for WordPress [wp-db-backup] < 2.5.2

unknown

[en] The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. This could lead to cases where attackers can send backup notification emails to themselves, whic...

Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Jun 6, 2022

CVE-2022-1577 on NVD →

Database Backup for WordPress <= 2.5.1 - Cross-Site Request Forgery to Settings Update

high

The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. This could lead to cases where attackers can send backup notification emails to themselves, which con...

CVSS:
8.8
Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
May 11, 2022

CVE-2022-1577 on NVD →

Database Backup for WordPress [wp-db-backup] < 2.5.1

unknown

[en] The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Feb 21, 2022

CVE-2022-0255 on NVD →

Database Backup for WordPress <= 2.5 - Admin+ SQL Injection

high

The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue

CVSS:
7.2
Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Jan 24, 2022

CVE-2022-0255 on NVD →

Database Backup for WordPress [wp-db-backup] < 2.4

unknown

[en] The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Jun 1, 2021

CVE-2021-24322 on NVD →

Database Backup for WordPress <= 2.3.3 - Authenticated Stored Cross-Site Scripting via backup_receipient Parameter

medium

The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.

CVSS:
5.4
Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
May 16, 2021

CVE-2021-24322 on NVD →

Database Backup for WordPress [wp-db-backup] < 2.4

unknown

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in Database Backup for WordPress plugin (versions <= 2.3.3).

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Apr 22, 2021

Database Backup for WordPress [wp-db-backup] < 2.3.0

unknown

[en] The wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read backup archives via a brute-force attack.

Affected:
up to 2.3.0
Fixed in:
2.3.0
Disclosed:
Oct 5, 2018

CVE-2014-10076 on NVD →

Database Backup for WordPress <= 2.2.4 - Missing Authorization

high

The wp-db-backup plugin up to 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read backup archives via a brute-force attack.

CVSS:
7.5
Affected:
up to 2.2.4
Fixed in:
2.3.0
Disclosed:
Nov 2, 2014

CVE-2014-10076 on NVD →

Database Backup for WordPress [wp-db-backup] <= 1.7

unknown

[en] Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plugin for WordPress 1.7 and earlier allows remote authenticated users with administrative privileges to read arbitrary files via a .. (dot dot) in the backup parameter to edit.php.

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Aug 17, 2006

CVE-2006-4208 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database