← WordPress Vulnerabilities
WordPress security by component

Backup and Restore

Backup and Restore is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published May 16, 2026; the highest CVE/CNA score is 8.7.

Plugin slug: backup-and-restore-for-wp

CVE-2021-47979: Backup and Restore: Arbitrary file deletion

Backup and Restore is affected by arbitrary file deletion. Exploitation requires an authenticated WordPress account. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is 1.0.3.

PublishedMay 16, 2026
Safe version guidanceSee mitigation notes
Safe version
May 16, 2026 CVE-2021-47979
Backup and Restore: Arbitrary file deletion
Backup and Restore is affected by arbitrary file deletion. Exploitation requires an authenticated WordPress account. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is 1.0.3.
See mitigation notes
CVE8.7
NVDPending