Backup Migration WordPress Plugin Unauthenticated Backup Download Vulnerability

Vulnerability

A vulnerability exists in the Backup Migration WordPress plugin in versions prior to 2.0.0. The plugin fails to correctly generate backup paths in certain server configurations, allowing unauthenticated users to access a log file that reveals the backup filename. This log file can be used to download the backup archive without authentication.

Impact

Exploitation of this vulnerability leads to unauthorized access to backup files, which may contain sensitive information.

Reproduction

The vulnerability can be reproduced under specific server configurations. After logging in as a WordPress administrator, navigate to the Backup Migration plugin panel and create a backup. Once the backup is complete, a log file named 'latest.log' is generated in the 'wp-content/backup-migration/backups/' directory. This log file, accessible to unauthenticated users, contains the name of the newly created backup file. The backup can then be downloaded using the filename provided in the log.

Remediation

Users are advised to update the Backup Migration WordPress plugin to version 2.0.0 or later.

Added: Nov 24, 2025, 6:19 AM
Updated: Nov 24, 2025, 11:16 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.6
remediation
7.7
relevance
1.1
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.