cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-database-backup wp-database-backup

Direction: ascending
Jun 07, 2024

WP Database Backup – Unlimited Database & Files Backup by Backup for WP # CVE-2022-2271

CVE, Research URL

CVE-2022-2271

Date
Sep 05, 2022
Research Description
The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
Min -, max -.
Status
vulnerable

WP Database Backup – Unlimited Database & Files Backup by Backup for WP # CVE-2020-7241

CVE, Research URL

CVE-2020-7241

Date
Jan 21, 2020
Research Description
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing random ID numbers, guessing date strings with a 2020_{0..1}{0..2}_{0..3}{0..9} format, guessing UNIX timestamps, and making HTTPS requests with the complete guessed URL.
Affected versions
Min -, max -.
Status
vulnerable
Jan 09, 2025

WP Database Backup – Unlimited Database & Files Backup by Backup for WP # CVE-2024-12330

CVE, Research URL

CVE-2024-12330

Date
Jan 09, 2025
Research Description
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.3 via publicly accessible back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including all information stored in the database.
Affected versions
Min -, max -.
Status
vulnerable
Jul 27, 2025

WP Database Backup – Unlimited Database & Files Backup by Backup for WP # CVE-2019-25224

CVE, Research URL

CVE-2019-25224

Date
Jul 25, 2025
Research Description
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
Affected versions
Min -, max -.
Status
vulnerable