← WordPress Vulnerabilities
WordPress security by component

WP Database Backup – Unlimited Database & Files Backup by Backup for WP

WP Database Backup – Unlimited Database & Files Backup by Backup for WP is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Jul 02, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: wp-database-backup

CVE-2026-9834: WP Database Backup – Unlimited Database & Files Backup by Backup for WP: Code execution

WP Database Backup – Unlimited Database & Files Backup by Backup for WP is affected by code execution. Exploitation requires at least administrator-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 7.11.

PublishedJul 02, 2026
Known safe version> 7.11
Safe version
Jul 02, 2026 CVE-2026-9834
WP Database Backup – Unlimited Database & Files Backup by Backup for WP: Code execution
WP Database Backup – Unlimited Database & Files Backup by Backup for WP is affected by code execution. Exploitation requires at least administrator-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 7.11.
> 7.11
CVE7.2
NVDPending
Jul 25, 2025 CVE-2019-25224
WP Database Backup: A security weakness
WP Database Backup is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVDPending
Sep 05, 2022 CVE-2022-2271
WP Database Backup: Cross-site scripting
WP Database Backup is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jan 20, 2020 CVE-2020-7241
Wp Database Backup: A security weakness
Wp Database Backup is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Aug 12, 2019 CVE-2019-14949
Wp Database Backup: Cross-site scripting
Wp Database Backup is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 12, 2019 CVE-2016-10876
Wp Database Backup: Cross-site request forgery
Wp Database Backup is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8
Aug 12, 2019 CVE-2016-10875
Wp Database Backup: Cross-site scripting
Wp Database Backup is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 12, 2019 CVE-2016-10874
Wp Database Backup: Cross-site request forgery
Wp Database Backup is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8
Aug 12, 2019 CVE-2016-10873
Wp Database Backup: Cross-site scripting
Wp Database Backup is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1