PT-2025-30720 · Databasebackup+2 · Wp Database Backup – Unlimited Database & Files Backup By Backup For Wp+2

Published

2025-07-25

·

Updated

2025-07-25

·

CVE-2019-25224

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Database Backup versions prior to 5.2
Description An OS Command Injection flaw exists in the mysqldump() function, allowing unauthenticated attackers to execute arbitrary commands on the host operating system.
Recommendations Update to version 5.2 or later. As a temporary workaround, consider disabling the mysqldump() function until the update is applied.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2019-25224

Affected Products

Wp Database Backup – Unlimited Database & Files Backup By Backup For Wp
Wp-Database-Backup
Wp Database Backup