Backwpup
Backwpup: vulnerabilidades y CVE
Backwpup tiene 7 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86815 | Media (5.5) | 0.38% | — | 11 sept 2026 | The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress… |
| CVE-2026-65443 | Alta (7.1) | 0.25% | — | 27 jul 2026 | Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions. |
| CVE-2026-6227 | Alta (7.2) | 1.0% | — | 14 abr 2026 | The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/backwpup/v1/getblock` REST endpoint in all versions up to, and including, 5.6.6 due to a… |
| CVE-2025-15041 | Alta (7.2) | 0.39% | — | 19 feb 2026 | The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the save_site_option()… |
| CVE-2025-10579 | Media (5.3) | 0.28% | — | 25 oct 2025 | The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'backwpup_working' AJAX action in all versions up to, and… |
| CVE-2011-5208 | Media (5) | 3.3% | — | 8 oct 2012 | Multiple directory traversal vulnerabilities in the BackWPup plugin before 1.4.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the wpabs parameter to (1)… |
| CVE-2011-4342 | Alta (7.5) | 11% | — | 8 oct 2012 | PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.