Access violation vulnerability in BackWPup – WordPress Backup & Restore Plugin 4.0.1

The BackWPup plugin used for WordPress has a security issue that can be exploited in versions up to 4.0.1. This vulnerability allows hackers with access to the system to save backup files in any location on the server, as long as they have permission to write to that location. By default, the plugin will create an index.php and .htaccess file in the chosen directory to prevent unauthorized access, but an attacker could use this to disable another website in a shared hosting environment.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.