VYPR

Backup Migration

by WordPress

CVEs (3)

  • CVE-2023-54346HigMay 5, 2026
    risk 0.49cvss 7.5epss 0.00

    WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated attackers to download complete database backups by accessing predictable file paths. Attackers can enumerate backup directories through configuration files and complete logs, then construct direct download URLs to retrieve sensitive backup archives containing full database dumps.

  • CVE-2025-12394MedNov 24, 2025
    risk 0.38cvss 5.9epss 0.00

    The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication.

  • CVE-2023-5738Nov 27, 2023
    risk 0.00cvss epss 0.00

    The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.