VYPR

JetBackup

by WordPress

CVEs (3)

  • CVE-2023-7165HigFeb 27, 2024
    risk 0.49cvss 7.5epss 0.02

    The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors to leak backup files.

  • CVE-2020-36667MedMar 7, 2023
    risk 0.35cvss 5.4epss 0.00

    The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location changes in versions up to, and including 1.4.1 due to a lack of proper capability checking on the backup_guard_cloud_dropbox, backup_guard_cloud_gdrive, and…

  • CVE-2026-4853MedApr 17, 2026
    risk 0.32cvss 4.9epss 0.01

    The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Directory Deletion in versions up to and including 3.1.19.8. This is due to insufficient input validation on the fileName parameter in the file upload handler.…