Backup Bolt WordPress Plugin Arbitrary File Download Vulnerability

Vulnerability

A vulnerability in the Backup Bolt plugin for WordPress, present in all versions through 1.4.1, allows authenticated users with Administrator-level access to download files from directories outside the webroot and to write backup zip files to arbitrary locations. This issue arises in the process_backup_batch() function, which is responsible for handling backup operations.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files outside the webroot, potentially including configuration files or other critical data. Additionally, the ability to write backup files to arbitrary locations could be misused to overwrite important files or disrupt the site's functionality.

Remediation

No known patch is available for this vulnerability. Users are advised to review the vulnerability details thoroughly and consider uninstalling the affected plugin.

Added: Oct 3, 2025, 12:54 PM
Updated: Oct 3, 2025, 12:54 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
5.0
remediation
0.0
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.