The Backup Migration plugin for WordPress is vulnerable to a security issue in versions 1.0.8 to 1.3.9. This issue allows unauthenticated attackers to gain access to the server and execute code. In order for an attacker to exploit this vulnerability, the target server’s php.ini must have ‘allow_url_include’ set to ‘on’. This feature is no longer available in newer versions of PHP, as it was disabled by default since version 7.4.