What this page helps you verify fast
This hub clusters tracked records for Backup Migration so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin Backup Migration (`backup-backup`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2026-39480, CVE-2025-14944 and CVE-2025-12394, so operators can jump from disclosure to patch validation without scanning the full feed first.
Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.
Review patch cadence, privileged access, XML-RPC exposure, backups, and monitoring controls.
Use ownership, update testing, least privilege, and removal criteria to reduce plugin risk.
Compare scanner coverage for plugin CVEs, version detection, alert noise, and remediation workflow.
Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.
Affected range: Versions up to 1.3.9. Fixed version: 1.4.0.
Affected range: Versions up to 1.3.7. Fixed version: 1.3.8.
Affected range: Versions up to 1.3.5. Fixed version: 1.3.6.
Affected range: Versions up to 1.4.6. Fixed version: 1.4.6.1.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
| Tracked CVE | Issue Type | Affected Versions | Fixed Version | CVSS |
|---|---|---|---|---|
|
CVE-2023-6972
Backup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File Deletio...
|
Remote Code Execution | Versions up to 1.3.9 | 1.4.0 | CVSS 9.8 |
|
CVE-2023-6553
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
|
Remote Code Execution | Versions up to 1.3.7 | 1.3.8 | CVSS 9.8 |
|
CVE-2023-6271
Backup Migration <= 1.3.5 - Unauthenticated Sensitive Information Exposure
|
Sensitive Information Exposure | Versions up to 1.3.5 | 1.3.6 | CVSS 9.8 |
|
CVE-2024-10932
Backup Migration <= 1.4.6 - Unauthenticated PHP Object Injection via 'recursive_unse...
|
Vulnerability | Versions up to 1.4.6 | 1.4.6.1 | CVSS 8.8 |
|
CVE-2023-6971
Backup Migration 1.0.8 - 1.3.9 - Remote File Inclusion via content-dir
|
Vulnerability | 1.0.8 through 1.3.9 | 1.4.0 | CVSS 8.1 |
|
CVE-2025-12394
Backup Migration <= 1.4.9 - Information Exposure to Unauthenticated Back-up Download
|
Sensitive Information Exposure | Versions up to 1.4.9 | 2.0.0 | CVSS 7.5 |
|
CVE-2023-6266
Backup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive I...
|
Sensitive Information Exposure | Versions up to 1.3.6 | 1.3.7 | CVSS 7.5 |
|
CVE-2023-7002
Backup Migration <= 1.3.9 - Authenticated (Admin+) OS Command Injection via url
|
Vulnerability | Versions up to 1.3.9 | 1.4.0 | CVSS 7.2 |
Backup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File Deletion
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
Backup Migration <= 1.3.5 - Unauthenticated Sensitive Information Exposure
Backup Migration <= 1.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialize_replace'
Backup Migration 1.0.8 - 1.3.9 - Remote File Inclusion via content-dir
Backup Migration <= 1.4.9 - Information Exposure to Unauthenticated Back-up Download
Backup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure
Backup Migration <= 1.3.9 - Authenticated (Admin+) OS Command Injection via url
This hub clusters tracked records for Backup Migration so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The BackupBliss – Backup & Migration with Free Cloud Storage plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.1. This makes it p...
The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to a missing capability check on the 'initializeOffl...
The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via an exposed log file containing paths to backups. Thi...
Sorted by latest disclosure date so newly published issues surface first.
The BackupBliss – Backup & Migration with Free Cloud Storage plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to a missing capability check on the 'initializeOfflineAjax' function and lack of proper nonce verification. The endpoint only validates again...
The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via an exposed log file containing paths to backups. This makes it possible for unauthenticated attackers to extract sensitive data including file...
The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP...
The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.3 via log files. This makes it possible for unauthenticated attackers to extract potentially sensitive information via log files.
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on...
The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. NOTE: Successful...
The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticate...
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that t...
The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5. This makes it possible for unauthenticated attackers to extract database backups leading to the potential for a complete site takeover.
The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated at...
The Backup Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.9. This is due to missing nonce validation on the ajax() function, or BMI_Ajax class. This makes it possible for unauthenticated attackers to control any of...