Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

WP Database Backup OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the WP Database Backup plugin for WordPress, affecting versions prior to 5.2. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system by exploiting the plugin's backup functionality. The issue arises because the plugin's 'mysqldump' command, used for database backups, includes unsanitized user input from the 'wp_db_exclude_table' parameter. As a result, injected commands are executed each time a backup is performed, with the malicious payload persisting until manually removed.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the server where the affected WordPress site is hosted.

Reproduction

To reproduce this vulnerability, first, update the 'wp_db_exclude_table' option with a command payload using an arbitrary option update vulnerability. Once the payload is stored, the command will be executed each time the WP Database Backup plugin creates a database backup, either manually or through the plugin's auto-backup feature.

Remediation

Users are advised to update the WP Database Backup plugin to version 5.2 or later.

Added: Jul 25, 2025, 3:22 AM
Updated: Jul 25, 2025, 3:22 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
10.0
exploitability
7.1
remediation
7.7
relevance
0.3
threat
9.7
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.