WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Backuply safe?

Backup, restores, and migration with Backuply are fairly simple with a wide range of storage options from Local Backups, FTP to cloud options like AWS …

What this plugin does

  • Slug: backuply
  • Author: Softaculous
  • 700000+ active installs
  • 90/100 rating (135 reviews on wordpress.org)
  • 6499919 all-time downloads
  • On WordPress.org since 2022-07-22

backupcloud backupdatabase backuprestorewordpress backup

Maintenance status

  • Last updated: 2026-07-21 12:28pm GMT
  • Tested up to WordPress: 7.0.2
  • Requires PHP: 5.5+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

5 known CVEs on file for Backuply. Reported between 2024 and 2025.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-10307 Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.4.9 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.5 < 1.4.9 1.4.9 2025-09-25
CVE-2024-8669 Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.3.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 1.3.5 1.3.5 2024-09-13
CVE-2024-2294 Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.2.8 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.9 < 1.2.8 1.2.8 2024-03-15
CVE-2024-0842 Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.2.7 Uncontrolled Resource Consumption High 7.5 < 1.2.7 1.2.7 2024-02-08
CVE-2024-0697 Backuply – Backup, Restore, Migrate and Clone [backuply] < 1.2.4 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.9 < 1.2.4 1.2.4 2024-01-26

CVE-2025-10307

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete backup functionality in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Source: CVE.org

CVE-2024-8669

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: CVE.org

CVE-2024-2294

Update the WordPress Backuply – Backup, Restore, Migrate and Clone plugin to the latest available version (at least 1.2.8). Dau Hoang Tai discovered and reported this Directory Traversal vulnerability in WordPress Backuply – Backup, Restore, Migrate and Clone Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files/directories exist in given folder. This can be used to exploit other weaknesses in the system This vulnerability has been fixed in version 1.2.8. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2024-0842

Update the WordPress Backuply – Backup, Restore, Migrate and Clone plugin to the latest available version (at least 1.2.6). villu164 discovered and reported this Denial of Service Attack vulnerability in WordPress Backuply – Backup, Restore, Migrate and Clone Plugin. A denial of service attack occurs when a malicious actor can cause the endpoint, or website, to crash or refuse to serve requests to one or more users by causing it to hang, crash or make unusable. This vulnerability has been fixed in version 1.2.6. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2024-0697

Update the WordPress Backuply – Backup, Restore, Migrate and Clone plugin to the latest available version (at least 1.2.4). Bence Szalai discovered and reported this Directory Traversal vulnerability in WordPress Backuply – Backup, Restore, Migrate and Clone Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files/directories exist in given folder. This can be used to exploit other weaknesses in the system This vulnerability has been fixed in version 1.2.4. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.