cleantalk
Vulnerabilities and Security Researches

WP Database Backup – Unlimited Database & Files Backup by Backup for WP, CVE-2019-25224

CVE, Research URL

CVE-2019-25224

Published on
Jul 25, 2025
Research Description
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
Affected versions
Min -, max 5.2.
Status
vulnerable