Backupbliss develops backup and migration software whose vulnerabilities skew toward serious outcomes, with a meaningful share reaching critical severity and a notable tendency toward public exploit availability. The recurring exposure centers on its Backup Migration and Clone products and clusters around access-control weaknesses—including missing authorization checks, cross-site request forgery, and improper file/directory permissions—that reflect the sensitive nature of backup data and the administrative interfaces through which backups are managed and restored. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Backupbliss over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6553CRITICAL The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to | Dec 15, 2023 | 9.8 | 93 | NO | YES |
CVE-2023-7002HIGH The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows auth | Dec 23, 2023 | 7.2 | 44 | NO | NO |
CVE-2023-6750HIGH The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path. | Jan 8, 2024 | 7.5 | 37 | NO | YES |
CVE-2023-6266HIGH The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading | Jan 11, 2024 | 7.5 | 32 | NO | YES |
CVE-2023-6972CRITICAL The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifes | Dec 23, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-6971CRITICAL The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenti | Dec 23, 2023 | 9.8 | 31 | NO | NO |
CVE-2024-43298HIGH Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5. | Nov 1, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-43297HIGH Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5. | Nov 1, 2024 | 8.8 | 23 | NO | NO |
CVE-2023-6271HIGH The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to | Jan 1, 2024 | 7.5 | 22 | NO | NO |
CVE-2021-36884MEDIUM Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions. | Nov 19, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Backupbliss.
Media articles that mention a CVE ID that affects a product developed by Backupbliss — matched by CVE ID, not by vendor name.