PT-2025-30126 · WordPress · Simple Backup

CVE-2015-10134

·

Published

2025-07-19

·

Updated

2025-07-19

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Simple Backup versions prior to 2.7.11
Description The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download due to a lack of capability checks and file type validation in the download backup file function. This allows attackers to download sensitive files, such as the wp-config.php file, from the affected site.
Recommendations Update the Simple Backup plugin to version 2.7.11 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-10134

Affected Products

Simple Backup