What the vulnerability does
01Description
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.6. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result in the server running out of resources.
Explanation of Vulnerability in Simple Terms
02Summary
Backuply versions up to 1.2.6 do not properly limit resource consumption, allowing an attacker to exhaust server resources without authentication. An attacker can send repeated requests to trigger excessive CPU, memory, or disk usage, causing the site to become slow or unresponsive. This affects all installations of the affected version.
What an attacker can do
03Attacker Capabilities
Make the site slow or unresponsive by consuming excessive server resources.
Potential impact on your site
04Site Impact
Your site may become unavailable or perform poorly during an attack without warning.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
February 9, 2024
CVE published
April 8, 2026
Record updated