Database Backup and Check Tables Automated With Scheduler 2024 Arbitrary File Deletion Vulnerability

Vulnerability

A vulnerability allowing arbitrary file deletion has been identified in the Database Backup and Check Tables Automated With Scheduler 2024 plugin for WordPress, affecting all versions through 2.35. This issue arises from inadequate file path validation in the 'database_backup_ajax_delete' function, enabling authenticated attackers with Administrator-level access and above to delete arbitrary files on the server. Such deletions could lead to remote code execution if critical files, like wp-config.php, are removed. Version 2.36 includes a partial patch for this vulnerability.

Impact

Exploitation of this vulnerability allows for arbitrary file deletion on the server. Deleting certain files, such as wp-config.php, could facilitate remote code execution.

Remediation

Users are advised to update the plugin to version 2.37 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.5
remediation
7.7
relevance
0.0
threat
3.3
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.