Extension WordPress
Vulnérabilités Database Backup for WordPress
Cette page rassemble les failles publiées pour Database Backup for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Database Backup for WordPress
7 fiches
Database Backup for WordPress <= 2.5.2 – Missing Authorization to Unauthenticated Database Export
The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check.…
*-2.5.2
2.5.3
13/05/2026
Database Backup for WordPress <= 2.5.2 – Missing Authorization to Unauthenticated Arbitrary File Read and Deletion
The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of…
*-2.5.2
2.5.3
13/05/2026
Database Backup for WordPress <= 2.5.2 – Missing Authorization to Unauthenticated Database Backup Interception
The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database…
*-2.5.2
2.5.3
13/05/2026
Database Backup for WordPress <= 2.5.1 – Cross-Site Request Forgery to Settings Update
The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack.…
[*, 2.5.2)
2.5.2
11/05/2022
Database Backup for WordPress <= 2.5 – Admin+ SQL Injection
The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue
[*, 2.5.1)
2.5.1
24/01/2022
Database Backup for WordPress <= 2.3.3 – Authenticated Stored Cross-Site Scripting via backup_receipient Parameter
The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.
[*, 2.4)
2.4
16/05/2021
Database Backup for WordPress <= 2.2.4 – Missing Authorization
The wp-db-backup plugin up to 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read backup archives via a brute-force attack.
*-2.2.4
2.3.0
02/11/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.