Input validation vulnerability in Bears Backup 2.0.0

The Bears Backup plugin for WordPress has a security issue that allows attackers to remotely run code on a website. This can result in the installation of harmful backdoors or the creation of unauthorized administrative accounts. This vulnerability affects all versions up to and including 2.0.0 and is caused by a function that does not properly check for user permissions or validate input. Additionally, on WordPress sites using the Alone theme versions 7.8.4 and older, this vulnerability can be combined with CVE-2025-5394 to install the Bears Backup plugin and cause the same damage.

Detected in:

Bears Backup fixed vulnerable versions: >= * <= 2.0.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.