WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Backuply?

Backup, restores, and migration with Backuply are fairly simple with a wide range of storage options from Local Backups, FTP to cloud options like AWS …

Qué hace este plugin

  • Slug: backuply
  • Autor: Softaculous
  • 700000+ instalaciones activas
  • 90/100 calificación (135 reseñas en wordpress.org)
  • 6499919 descargas totales
  • En WordPress.org desde 2022-07-22

backupcloud backupdatabase backuprestorewordpress backup

Estado de mantenimiento

  • Última actualización: 2026-07-21 12:28pm GMT
  • Probado hasta WordPress: 7.0.2
  • Requiere PHP: 5.5+
  • PHP máximo soportado (analizado): <8.0

Vulnerabilidades conocidas

5 CVEs conocidos registrados para Backuply. Reportadas entre 2024 y 2025.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2025-10307 Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.4.9 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 6,5 < 1.4.9 1.4.9 2025-09-25
CVE-2024-8669 Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.3.5 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 7,2 < 1.3.5 1.3.5 2024-09-13
CVE-2024-2294 Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.2.8 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 4,9 < 1.2.8 1.2.8 2024-03-15
CVE-2024-0842 Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.2.7 Consumo de recursos no controlado Alta 7,5 < 1.2.7 1.2.7 2024-02-08
CVE-2024-0697 Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.2.4 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 4,9 < 1.2.4 1.2.4 2024-01-26

CVE-2025-10307

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete backup functionality in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-8669

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-2294

Update the WordPress Backuply – Backup, Restore, Migrate and Clone plugin to the latest available version (at least 1.2.8). Dau Hoang Tai discovered and reported this Directory Traversal vulnerability in WordPress Backuply – Backup, Restore, Migrate and Clone Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files/directories exist in given folder. This can be used to exploit other weaknesses in the system This vulnerability has been fixed in version 1.2.8. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-0842

Update the WordPress Backuply – Backup, Restore, Migrate and Clone plugin to the latest available version (at least 1.2.6). villu164 discovered and reported this Denial of Service Attack vulnerability in WordPress Backuply – Backup, Restore, Migrate and Clone Plugin. A denial of service attack occurs when a malicious actor can cause the endpoint, or website, to crash or refuse to serve requests to one or more users by causing it to hang, crash or make unusable. This vulnerability has been fixed in version 1.2.6. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-0697

Update the WordPress Backuply – Backup, Restore, Migrate and Clone plugin to the latest available version (at least 1.2.4). Bence Szalai discovered and reported this Directory Traversal vulnerability in WordPress Backuply – Backup, Restore, Migrate and Clone Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files/directories exist in given folder. This can be used to exploit other weaknesses in the system This vulnerability has been fixed in version 1.2.4. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.