Wpbackitup develops a WordPress backup and restoration plugin with a focused vulnerability footprint centered on cross-site request forgery weaknesses in its administrative interfaces. The recurring exposure reflects the plugin's role in managing sensitive site operations, where CSRF protections are critical to prevent unauthorized backup deletion or restoration. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpbackitup over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7232MEDIUM The Backup and Restore WordPress WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenti | Mar 26, 2024 | 5.3 | 18 | NO | NO |
CVE-2024-43270MEDIUM Missing Authorization vulnerability in WPBackItUp Backup and Restore WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Backup and Restore | Nov 1, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-43268MEDIUM Access Control vulnerability in WPBackItUp Backup and Restore WordPress allows .
This issue affects Backup and Restore WordPress: from n/a through 1.50. | Nov 1, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-43269MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50. | Aug 26, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpbackitup.
Media articles that mention a CVE ID that affects a product developed by Wpbackitup — matched by CVE ID, not by vendor name.