What the vulnerability does
01Description
WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated attackers to download complete database backups by accessing predictable file paths. Attackers can enumerate backup directories through configuration files and complete logs, then construct direct download URLs to retrieve sensitive backup archives containing full database dumps.
Explanation of Vulnerability in Simple Terms
02Summary
The Backup Migration plugin for WordPress contains a vulnerability that exposes sensitive backup files. An attacker on the network can access these files without authentication or user interaction. The vulnerability affects versions 1.2.8 and requires immediate patching to prevent unauthorized access to site backups.
What an attacker can do
03Attacker Capabilities
Read backup files containing sensitive site data without logging in.
Potential impact on your site
04Site Impact
Attackers can download complete site backups, exposing databases, user data, and configuration files.
Conditions required to exploit
05Prerequisites
Network access to the WordPress site; no authentication required.
Key dates
06Disclosure timeline
May 5, 2026
CVE published
May 6, 2026
Record updated