← WordPress Vulnerabilities
WordPress security by component

Backup Migration

Backup Migration is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: backup-backup

CVE-2026-39480: Backup Migration: A security weakness

Backup Migration is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.1.1.

PublishedJun 15, 2026
Known safe version2.1.2
Safe version
Jun 15, 2026 CVE-2026-39480
Backup Migration: A security weakness
Backup Migration is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.1.1.
2.1.2
CVE7.5
NVDPending
Apr 07, 2026 CVE-2025-14944
BackupBliss – Backup & Migration with Free Cloud Storage: A security weakness
BackupBliss – Backup & Migration with Free Cloud Storage is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.0.0.
> 2.0.0
CVE5.3
NVDPending
Jan 04, 2025 CVE-2024-10932
Backup Migration: Code execution
Backup Migration is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Apr 18, 2024 CVE-2024-32686
Backup Migration: A security weakness
Backup Migration is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 11, 2024 CVE-2023-6266
Backup Migration: A security weakness
Backup Migration is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Dec 23, 2023 CVE-2023-7002
Backup Migration: A security weakness
Backup Migration is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.2
NVD7.2
Dec 23, 2023 CVE-2023-6972
Backup Migration: Filesystem traversal
Backup Migration is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE9.8
NVD9.8
Dec 23, 2023 CVE-2023-6971
Backup Migration: A security weakness
Backup Migration is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.1
NVD9.8
Dec 15, 2023 CVE-2023-6553
Backup Migration: Code execution
Backup Migration is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVD9.8
Nov 19, 2021 CVE-2021-36884
Backup Backup: Cross-site scripting
Backup Backup is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD5.4