Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)2.7%—Wpseeds WP Database BackupAI2/7/20262/7/2026
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to and including 7.11 via the `wp_db_exclude_table` parameter. This is due to the direct concatenation of user-supplied `$_POST['wp_db_exclude_table']` values into…
AplazadaAlta (7.5)0.57%—Database Backup FOR WordpressAI14/5/202617/6/2026
The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database backups are written. This makes it possible for unauthenticated…
AplazadaAlta (8.1)0.57%—Database Backup FOR WordpressAI14/5/202617/6/2026
The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter.…
AplazadaAlta (7.5)0.50%—Deliciousbrains Database BackupAI14/5/202617/6/2026
The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check. This makes it possible for unauthenticated attackers to export database tables,…
AnalizadaCrítica (9.8)21%—Wpseeds WP Database Backup25/7/202517/6/2026
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
AplazadaAlta (7.2)1.0%—Database Backup AND Check Tables Automated With SchedulerAI1/3/202517/6/2026
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'database_backup_ajax_delete' function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.2)0.59%—Database Backup AND Check Tables Automated With Scheduler 2024AI1/3/202517/6/2026
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35 via the /dashboard/backup.php file. This makes it possible for authenticated attackers, with Administrator-level access and above, to…
AplazadaAlta (7.5)0.51%—Wpseeds WP Database BackupAI9/1/202517/6/2026
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.3 via publicly accessible back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including all…
AplazadaMedia (4.9)0.85%—Database Backup AND Check Tables Automated With SchedulerAI24/12/202417/6/2026
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.32 via the database_backup_ajax_download() function. This makes it possible for authenticated attackers, with administrator-level access and above, to…
ModificadaMedia (4.8)0.51%—Wpseeds WP Database Backup5/9/202217/6/2026
The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (5.4)0.42%—Deliciousbrains Database Backup8/6/202217/6/2026
The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. This could lead to cases where attackers can send backup notification emails to themselves, which…
ModificadaAlta (7.2)1.3%—Deliciousbrains Database Backup21/2/202217/6/2026
The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue
ModificadaMedia (5.4)0.70%—Deliciousbrains Database Backup1/6/202117/6/2026
The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.
ModificadaAlta (8.1)3.2%—Database-backups Project Database-backups5/4/202117/6/2026
The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups.
ModificadaAlta (7.5)2.4%—Wpseeds WP Database Backup20/1/202017/6/2026
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing random ID numbers, guessing date strings with a 2020_{0..1}{0..2}_{0..3}{0..9} format, guessing UNIX timestamps, and…
ModificadaMedia (6.1)0.95%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 5.1.2 for WordPress has XSS.
ModificadaAlta (8.8)0.69%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.
ModificadaMedia (6.1)0.92%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 4.3.1 for WordPress has XSS.
ModificadaAlta (8.8)0.68%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
ModificadaMedia (6.1)0.92%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 4.3.3 for WordPress has XSS.