Extension WordPress
Vulnérabilités Backup Migration
Cette page rassemble les failles publiées pour Backup Migration, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Backup Migration
17 fiches
BackupBliss – Backup & Migration with Free Cloud Storage <= 2.1.1 – Unauthenticated Information Exposure
The BackupBliss – Backup & Migration with Free Cloud Storage plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to extract sensitive user…
*-2.1.1
2.1.2
08/04/2026
Backup Migration <= 2.0.0 – Missing Authorization to Unauthenticated Backup Upload to Offline Storage
The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to a missing capability check on the 'initializeOfflineAjax' function and lack of proper nonce verification. The…
*-2.0.0
2.1.0
06/04/2026
Backup Migration <= 1.4.9 – Information Exposure to Unauthenticated Back-up Download
The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via an exposed log file containing paths to backups. This makes it possible for unauthenticated attackers to extract…
*-1.4.9
2.0.0
03/11/2025
Backup Migration <= 1.4.6 – Unauthenticated PHP Object Injection via 'recursive_unserialize_replace'
The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject…
*-1.4.6
1.4.6.1
03/01/2025
Backup Migration <= 1.4.3 – Information Exposure via Log Files
The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.3 via log files. This makes it possible for unauthenticated attackers to extract potentially sensitive information via log files.
*-1.4.3
1.4.4
17/04/2024
Inisev Analyst Module <= Various Versions – Missing Authorization
Multiple plugins and/or themes by Inisev for WordPress are vulnerable to unauthorized access due to a missing capability check on several functions in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
*-1.4.1
1.4.2
10/04/2024
Backup Migration <= 1.3.9 – Authenticated (Admin+) OS Command Injection via url
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands…
*-1.3.9
1.4.0
22/12/2023
Backup Migration 1.0.8 – 1.3.9 – Remote File Inclusion via content-dir
The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in…
1.0.8-1.3.9
1.4.0
22/12/2023
Backup Migration <= 1.3.9 – Unauthenticated Path Traversal to Arbitrary File Deletion
The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers…
*-1.3.9
1.4.0
22/12/2023
Backup Migration <= 1.3.7 – Unauthenticated Remote Code Execution
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to…
*-1.3.7
1.3.8
11/12/2023
Backup Migration <= 1.3.5 – Unauthenticated Sensitive Information Exposure
The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5. This makes it possible for unauthenticated attackers to extract database backups leading to the potential for a complete…
*-1.3.5
1.3.6
07/12/2023
Backup Migration <= 1.3.6 – Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure
The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This makes…
*-1.3.6
1.3.7
30/11/2023
Backup Migration <= 1.2.9 – Cross-Site Request Forgery
The Backup Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.9. This is due to missing nonce validation on the ajax() function, or BMI_Ajax class. This makes it possible for…
[*, 1.3.0)
1.3.0
05/09/2023
Inisev Plugins (Various Versions) – Missing Authorization on handle_installation function
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible…
*-1.2.7
1.2.8
27/07/2023
Inisev Plugins (Various Versions) – Cross-Site Request Forgery on handle_installation function
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions.…
*-1.2.7
1.2.8
27/07/2023
Backup Migration <= 1.2.8 – Sensitive Information Exposure
The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.8 via config and log files in the wp-content/backup-migration/ folder. This can allow unauthenticated attackers to extract sensitive data in…
*-1.2.8
1.2.9
10/05/2023
Backup Migration <= 1.1.5 – Authenticated (Admin+) Stored Cross-Site Scripting
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin
*-1.1.5
1.1.6
17/11/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.