VendorsiThemesbackupbuddyall versions
Vulnerabilities

iThemes BackupBuddy

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-31474
WordPress BackupBuddy Plugin 8.5.8.0-8.7.4.1 is vulnerable to Directory Traversal
Published 2023-03-13 · Modified
7.5EPSS 0.638
CVE-2013-2741
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1) direct request, (2) step=1 request, (3) step=2 or step=3 request, or (4) step=7 request.
Published 2013-04-02 · Modified
7.5EPSS 0.026
CVE-2013-2743
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via a crafted integer in the step parameter.
Published 2013-04-02 · Modified
7.5EPSS 0.026
CVE-2013-2742
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after completing a restore operation, which makes it easier for remote attackers to obtain access via subsequent requests to this script.
Published 2013-04-02 · Modified
7.5EPSS 0.024
CVE-2022-4897
BackupBuddy < 8.8.3 - Multiple Reflected Cross-Site Scripting
Published 2023-02-21 · Modified
6.1EPSS 0.009
CVE-2013-2744
importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote attackers to obtain configuration information via a step 0 phpinfo action, which calls the phpinfo function.
Published 2013-04-02 · Modified
5.0EPSS 0.021