← WordPress Vulnerabilities
WordPress security by component

Backuply – Backup, Restore, Migrate and Clone

Backuply – Backup, Restore, Migrate and Clone is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Sep 14, 2024; the highest CVE/CNA score is 9.1.

Plugin slug: backuply

CVE-2024-8669: Backuply – Backup, Restore, Migrate and Clone: SQL injection

Backuply – Backup, Restore, Migrate and Clone is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.

PublishedSep 14, 2024
Safe version guidanceSee mitigation notes
Safe version
Sep 14, 2024 CVE-2024-8669
Backuply – Backup, Restore, Migrate and Clone: SQL injection
Backuply – Backup, Restore, Migrate and Clone is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.1
NVD7.2
Mar 16, 2024 CVE-2024-2294
Backuply – Backup, Restore, Migrate and Clone: Filesystem traversal
Backuply – Backup, Restore, Migrate and Clone is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVDPending
Feb 09, 2024 CVE-2024-0842
Backuply – Backup, Restore, Migrate and Clone: A security weakness
Backuply – Backup, Restore, Migrate and Clone is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Jan 27, 2024 CVE-2024-0697
Backuply – Backup, Restore, Migrate and Clone: Filesystem traversal
Backuply – Backup, Restore, Migrate and Clone is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.5
NVD4.9