Vulnerabilities (CVE)

Filtered by vendor Backupbliss Subscribe
Filtered by product Backup Migration
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6271 1 Backupbliss 1 Backup Migration 2024-01-08 N/A 7.5 HIGH
The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.
CVE-2023-7002 1 Backupbliss 1 Backup Migration 2023-12-29 N/A 7.2 HIGH
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system.