CVE-2024-0842 HIGH

CVE-2024-0842: Backuply - Backup, Restore, Migrate and Clone <= 1.2.6 - Denial of Service

Vendor Softaculous
Product Backuply – Backup, Restore, Migrate and Clone
Weakness CWE-400
Published February 9, 2024
Last update April 8, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.6. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result in the server running out of resources.

Explanation of Vulnerability in Simple Terms

02Summary

Backuply versions up to 1.2.6 do not properly limit resource consumption, allowing an attacker to exhaust server resources without authentication. An attacker can send repeated requests to trigger excessive CPU, memory, or disk usage, causing the site to become slow or unresponsive. This affects all installations of the affected version.

What an attacker can do

03Attacker Capabilities

Make the site slow or unresponsive by consuming excessive server resources.

Potential impact on your site

04Site Impact

Your site may become unavailable or perform poorly during an attack without warning.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

February 9, 2024 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE