CVE-2024-12330
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.3 via publicly accessible back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including all information stored in the database.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.51%
- CWE
- CWE-530
- Published
- 2025-01-09
- Last modified
- 2026-04-09
Affected products
- databasebackup WP Database Backup – Unlimited Database & Files Backup by Backup for WP
- databasebackup WP Database Backup – Unlimited Database & Files Backup by Backup for WP
Weakness type
Related vulnerabilities
- CVE-2026-13514 — Chess Play and Learn App com.chess AndroidManifest.xml backup
- CVE-2024-56462 — IBM QRadar SIEM is vulnerable to using components with known vulnerabilities
- CVE-2026-2974 — AliasVault App Backup aliasvault.xml backup
- CVE-2020-36899 — QiHang Media Web Digital Signage 3.0.9 Unauthenticated Arbitrary File Disclosure
- CVE-2025-3773 — A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and...
- CVE-2024-3430 — QKSMS Backup File androidmanifest.xml backup
- CVE-2024-3128 — Replify-Messenger Backup File androidmanifest.xml backup
- CVE-2024-3124 — fridgecow smartalarm Backup File androidmanifest.xml backup