cleantalk
Vulnerabilities and Security Researches

Backup Migration, CVE-2025-12394

CVE, Research URL

CVE-2025-12394

Application

Backup Migration

Published on
Nov 24, 2025
Research Description
The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication.
Affected versions
max 2.0.0.
Status
vulnerable