CVE · High

CVE-2024-8669 — Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.3.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8669 Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.3.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 1.3.5 1.3.5 2024-09-13

CVE-2024-8669

The Backuply plugin for WordPress contains a security flaw in its backup functionality, specifically within the backuply_wp_clone_sql() function, which processes user-submitted data without proper protection against malicious input. This weakness allows attackers with elevated privileges to inject unauthorized SQL code into existing queries, potentially leading to sensitive database information being compromised. The vulnerability affects all versions of Backuply up to and including 1.3.4.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.