Input validation vulnerability in Backup and Restore WordPress – Backup Plugin 1.50

The Backup and Restore WordPress plugin, which is used to save and recover data on WordPress websites, has a security issue in versions up to and including 1.50. This is because it does not properly check for a unique security code when performing certain functions. As a result, hackers who are not logged in to the website can make the website administrator unknowingly take actions that they did not authorize, as long as they can trick the administrator into clicking a link.

Detected in:

Backup and Restore WordPress – Backup Plugin fixed vulnerable versions: >= * <= 1.50
WP BackItUp Community Edition fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.