Resources /
WordPress Plugins /
Backuply
PLUGIN SECURITY
Is Backuply safe?
Backup, restores, and migration with Backuply are fairly simple with a wide range of storage options from Local Backups, FTP to cloud options like AWS …
What this plugin does
- Slug:
backuply
- Author: Softaculous
- 700000+ active installs
- 90/100 rating (135 reviews on wordpress.org)
- 6499919 all-time downloads
- On WordPress.org since 2022-07-22
backupcloud backupdatabase backuprestorewordpress backup
Maintenance status
- Last updated: 2026-07-21 12:28pm GMT
- Tested up to WordPress: 7.0.2
- Requires PHP: 5.5+
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
5 known CVEs on file for Backuply.
Reported between 2024 and 2025.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-10307
|
Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.4.9 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Medium
6.5
|
< 1.4.9
|
1.4.9 |
2025-09-25 |
—
|
|
CVE-2024-8669
|
Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.3.5 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
7.2
|
< 1.3.5
|
1.3.5 |
2024-09-13 |
—
|
|
CVE-2024-2294
|
Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.2.8 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Medium
4.9
|
< 1.2.8
|
1.2.8 |
2024-03-15 |
—
|
|
CVE-2024-0842
|
Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.2.7 |
Uncontrolled Resource Consumption |
High
7.5
|
< 1.2.7
|
1.2.7 |
2024-02-08 |
—
|
|
CVE-2024-0697
|
Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.2.4 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Medium
4.9
|
< 1.2.4
|
1.2.4 |
2024-01-26 |
—
|
CVE-2025-10307
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete backup functionality in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Source:
CVE.org
CVE-2024-8669
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Source:
CVE.org
CVE-2024-2294
Update the WordPress Backuply – Backup, Restore, Migrate and Clone plugin to the latest available version (at least 1.2.8).
Dau Hoang Tai discovered and reported this Directory Traversal vulnerability in WordPress Backuply – Backup, Restore, Migrate and Clone Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files/directories exist in given folder. This can be used to exploit other weaknesses in the system This vulnerability has been fixed in version 1.2.8.
Have additional information or questions about this entry? Get in touch.
Source:
Patchstack
CVE-2024-0842
Update the WordPress Backuply – Backup, Restore, Migrate and Clone plugin to the latest available version (at least 1.2.6).
villu164 discovered and reported this Denial of Service Attack vulnerability in WordPress Backuply – Backup, Restore, Migrate and Clone Plugin. A denial of service attack occurs when a malicious actor can cause the endpoint, or website, to crash or refuse to serve requests to one or more users by causing it to hang, crash or make unusable. This vulnerability has been fixed in version 1.2.6.
Have additional information or questions about this entry? Get in touch.
Source:
Patchstack
CVE-2024-0697
Update the WordPress Backuply – Backup, Restore, Migrate and Clone plugin to the latest available version (at least 1.2.4).
Bence Szalai discovered and reported this Directory Traversal vulnerability in WordPress Backuply – Backup, Restore, Migrate and Clone Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files/directories exist in given folder. This can be used to exploit other weaknesses in the system This vulnerability has been fixed in version 1.2.4.
Have additional information or questions about this entry? Get in touch.
Source:
Patchstack
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.