VendorsWpseedswp_database_backupall versions
Vulnerabilities

Wpseeds Wp Database Backup

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2019-25224
WP Database Backup < 5.2 - Unauthenticated OS Command Injection
Published 2025-07-25 · Analyzed
9.8EPSS 0.214
CVE-2016-10876
The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.
Published 2019-08-12 · Modified
8.8EPSS 0.007
CVE-2016-10874
The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
Published 2019-08-12 · Modified
8.8EPSS 0.007
CVE-2020-7241
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing random ID numbers, guessing date strings with a 2020_{0..1}{0..2}_{0..3}{0..9} format, guessing UNIX timestamps, and making HTTPS requests with the complete guessed URL.
Published 2020-01-20 · Modified
7.5EPSS 0.024
CVE-2019-14949
The wp-database-backup plugin before 5.1.2 for WordPress has XSS.
Published 2019-08-12 · Modified
6.1EPSS 0.009
CVE-2016-10873
The wp-database-backup plugin before 4.3.3 for WordPress has XSS.
Published 2019-08-12 · Modified
6.1EPSS 0.009
CVE-2016-10875
The wp-database-backup plugin before 4.3.1 for WordPress has XSS.
Published 2019-08-12 · Modified
6.1EPSS 0.009
CVE-2022-2271
WP Database Backup < 5.9 - Admin+ Stored Cross-Site Scripting
Published 2022-09-05 · Modified
4.8EPSS 0.005