Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesDatabase Backup for WordPress

Database Backup for WordPress vulnerabilities

Database Backup for WordPress has 4 known vulnerabilities in this database. The most recent published record is dated 14 May 2026.

Known vulnerabilities
4
Active installs
60,000+
Latest version
2.5.3
Last updated
20 Apr 2026
Most recent
14 May 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Broken access control
CVE-2026-4029
High 7.5Up to 2.5.2Fixed in a later version (latest 2.5.3)14 May 2026
Arbitrary file read
CVE-2026-4030
High 8.1Up to 2.5.2Fixed in a later version (latest 2.5.3)14 May 2026
Sensitive data exposure
CVE-2026-4031
High 7.5Up to 2.5.2Fixed in a later version (latest 2.5.3)14 May 2026
Sensitive data exposure
CVE-2014-10076
High 7.5Not yet publishedCheck for an update5 Oct 2018
Read the published descriptions
CVE-2026-4029, 14 May 2026
The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check. This makes it possible for unauthenticated attackers to export database tables, leading to Sensitive Information Exposure. Note: This vulnerability is only exploitable in WordPress Multisite environments where the deprecated is_site_admin() function exists. CVE record
CVE-2026-4030, 14 May 2026
The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter. This makes it possible for unauthenticated attackers to read and delete arbitrary files on the server, leading to Sensitive Information Exposure and potential site takeover. Note: This vulnerability is only exploitable in WordPress Multisite environments where the deprecated is_site_admin() function exists. CVE record
CVE-2026-4031, 14 May 2026
The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database backups are written. This makes it possible for unauthenticated attackers to send a request to wp-cron.php with a poisoned wp_db_temp_dir value pointing to a publicly accessible directory (e.g., wp-content/uploads/), and if a scheduled backup is due, intercept the backup file before it is cleaned up. The backup file has a predictable name based on the database name, table prefix, date, and Swatch Internet Time, making interception reliable. Successful exploitation leads to Sensitive Information Exposure including database credentials, user password hashes, and personally identifiable information. This vulnerability requires that the site administrator has configured scheduled backups. CVE record
CVE-2014-10076, 5 Oct 2018
The wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read backup archives via a brute-force attack. CVE record

What to do if you run Database Backup for WordPress

If you run Database Backup for WordPress, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Database Backup for WordPress vulnerabilities

Free. We email you when a new vulnerability is published for Database Backup for WordPress, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support