← WordPress Vulnerabilities
WordPress security by component

BackUpWordPress

BackUpWordPress is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Apr 27, 2024; the highest CVE/CNA score is 4.3.

Plugin slug: backupwordpress

CVE-2024-3034: BackUpWordPress: Filesystem traversal

BackUpWordPress is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.

PublishedApr 27, 2024
Safe version guidanceSee mitigation notes
Safe version
Apr 27, 2024 CVE-2024-3034
BackUpWordPress: Filesystem traversal
BackUpWordPress is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE2.7
NVDPending
Mar 07, 2023 CVE-2022-4931
BackupWordPress: Sensitive information exposure
BackupWordPress is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVD4.3