What this page helps you verify fast
This hub clusters tracked records for Backuply – Backup, Restore, Migrate and Clone so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin Backuply – Backup, Restore, Migrate and Clone (`backuply`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2025-10307, CVE-2024-8669 and CVE-2024-2294, so operators can jump from disclosure to patch validation without scanning the full feed first.
Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.
Review patch cadence, privileged access, XML-RPC exposure, backups, and monitoring controls.
Use ownership, update testing, least privilege, and removal criteria to reduce plugin risk.
Compare scanner coverage for plugin CVEs, version detection, alert noise, and remediation workflow.
Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.
Affected range: Versions up to 1.3.4. Fixed version: 1.3.5.
Affected range: Versions up to 1.2.6. Fixed version: 1.2.7.
Affected range: Versions up to 1.4.8. Fixed version: 1.4.9.
Affected range: Versions up to 1.2.3. Fixed version: 1.2.4.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
| Tracked CVE | Issue Type | Affected Versions | Fixed Version | CVSS |
|---|---|---|---|---|
|
CVE-2024-8669
Backuply – Backup, Restore, Migrate and Clone <= 1.3.4 - Authenticated (Admin+) SQL...
|
SQL Injection | Versions up to 1.3.4 | 1.3.5 | CVSS 9.1 |
|
CVE-2024-0842
Backuply - Backup, Restore, Migrate and Clone <= 1.2.6 - Denial of Service
|
Vulnerability | Versions up to 1.2.6 | 1.2.7 | CVSS 7.5 |
|
CVE-2025-10307
Backuply – Backup, Restore, Migrate and Clone <= 1.4.8 - Authenticated (Admin+) Arbi...
|
Remote Code Execution | Versions up to 1.4.8 | 1.4.9 | CVSS 6.5 |
|
CVE-2024-0697
Backuply – Backup, Restore, Migrate and Clone <= 1.2.3 - Authenticated (Administrato...
|
Vulnerability | Versions up to 1.2.3 | 1.2.4 | CVSS 6.5 |
|
CVE-2024-2294
Backuply – Backup, Restore, Migrate and Clone <= 1.2.7 - Authenticated (Admin+) Dire...
|
Vulnerability | Versions up to 1.2.7 | 1.2.8 | CVSS 4.9 |
Backuply – Backup, Restore, Migrate and Clone <= 1.3.4 - Authenticated (Admin+) SQL Injection
Backuply - Backup, Restore, Migrate and Clone <= 1.2.6 - Denial of Service
Backuply – Backup, Restore, Migrate and Clone <= 1.4.8 - Authenticated (Admin+) Arbitrary File Deletion
Backuply – Backup, Restore, Migrate and Clone <= 1.2.3 - Authenticated (Administrator+) Directory Traversal
Backuply – Backup, Restore, Migrate and Clone <= 1.2.7 - Authenticated (Admin+) Directory Traversal
This hub clusters tracked records for Backuply – Backup, Restore, Migrate and Clone so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete backup functionality in...
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versio...
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.7 via the backup_name parameter in the b...
Sorted by latest disclosure date so newly published issues surface first.
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete backup functionality in all versions up to, and including, 1.4.8. This makes it possible for authenticated attack...
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on the user supplied parameter...
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.7 via the backup_name parameter in the backuply_download_backup function. This makes it possible for attackers to have an account...
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.6. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to ma...
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.3 via the node_id parameter in the backuply_get_jstree function. This makes it possible for attackers with administrator privilege...