The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
History

Mon, 11 Aug 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Wpseeds
Wpseeds wp Database Backup
CPEs cpe:2.3:a:wpseeds:wp_database_backup:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpseeds
Wpseeds wp Database Backup

Fri, 25 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Jul 2025 03:15:00 +0000

Type Values Removed Values Added
Description The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
Title WP Database Backup < 5.2 - Unauthenticated OS Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-07-25T02:23:58.569Z

Updated: 2025-07-25T17:12:05.066Z

Reserved: 2025-07-24T14:06:18.352Z

Link: CVE-2019-25224

cve-icon Vulnrichment

Updated: 2025-07-25T17:11:54.295Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-25T03:15:32.690

Modified: 2025-08-11T18:57:45.277

Link: CVE-2019-25224

cve-icon Redhat

No data.