VYPR

Backup Migration WordPress plugin

by Backup Migration

CVEs (1)

  • CVE-2025-12394MedNov 24, 2025
    risk 0.38cvss 5.9epss 0.00

    The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication.