Backupbliss
Backupbliss Backup Migration: vulnerabilidades y CVE
Backupbliss Backup Migration tiene 16 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses6
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-18216 | Media (6.5) | 0.51% | — | 15 ago 2026 | The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived… |
| CVE-2026-7693 | Alta (7.2) | 3.0% | — | 5 ago 2026 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `restoreBackup()` AJAX… |
| CVE-2026-39480 | Alta (7.5) | 0.42% | — | 15 jun 2026 | Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions. |
| CVE-2026-7566 | Media (6.6) | 0.78% | — | 6 jun 2026 | The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for… |
| CVE-2025-14944 | Media (5.3) | 0.56% | — | 7 abr 2026 | The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to a missing capability check on the 'initializeOfflineAjax' function and lack of… |
| CVE-2025-12394 | Media (5.9) | 0.28% | — | 24 nov 2025 | The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The… |
| CVE-2024-10932 | Alta (8.8) | 0.80% | — | 4 ene 2025 | The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This… |
| CVE-2023-6266 | Alta (7.5) | 2.1% | — | 11 ene 2024 | The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and… |
| CVE-2023-6271 | Alta (7.5) | 0.69% | — | 1 ene 2024 | The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the… |
| CVE-2023-7002 | Alta (7.2) | 31% | — | 23 dic 2023 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with… |
| CVE-2023-6972 | Crítica (9.8) | 1.4% | — | 23 dic 2023 | The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and… |
| CVE-2023-6971 | Crítica (9.8) | 6.4% | — | 23 dic 2023 | The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files… |
| CVE-2023-6553 | Crítica (9.8) | 98% | — | 15 dic 2023 | The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the… |
| CVE-2023-3977 | Media (4.3) | 0.61% | — | 28 jul 2023 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the… |
| CVE-2023-0958 | Media (6.5) | 0.69% | — | 28 jul 2023 | Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton… |
| CVE-2021-36884 | Media (5.4) | 0.57% | — | 19 nov 2021 | Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.