cleantalk
Vulnerabilities and Security Researches

Backup Bolt, CVE-2025-10306

CVE, Research URL

CVE-2025-10306

Application

Backup Bolt

Published on
Oct 03, 2025
Research Description
The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4.1 via the process_backup_batch() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to download directories outside of the webroot and write backup zip files to arbitrary locations.
Affected versions
max 1.4.1.
Status
vulnerable