Input validation vulnerability in Backup Migration 1.3.9

The Backup Migration plugin for WordPress is vulnerable to a security issue in versions 1.0.8 to 1.3.9. This issue allows unauthenticated attackers to gain access to the server and execute code. In order for an attacker to exploit this vulnerability, the target server’s php.ini must have ‘allow_url_include’ set to ‘on’. This feature is no longer available in newer versions of PHP, as it was disabled by default since version 7.4.

Detected in:

Backup Migration fixed vulnerable versions: >= 1.0.8 <= 1.3.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.