PT-2025-39952 · WordPress · Bei Fen – Wordpress Backup Plugin

Aril Aprilio

·

Published

2025-09-30

·

Updated

2025-10-05

·

CVE-2025-9993

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bei Fen – WordPress Backup Plugin versions through 1.4.2
Description The Bei Fen – WordPress Backup Plugin for WordPress is susceptible to Local File Inclusion through the task parameter. Attackers with Subscriber-level access or higher can include and execute arbitrary .php files on the server. This could allow bypassing access controls, obtaining sensitive data, or achieving code execution if .php file uploads and inclusion are permitted. This issue affects systems running PHP 7.1 or older.
Recommendations Update Bei Fen – WordPress Backup Plugin to a version later than 1.4.2. For systems running PHP 7.1 or older, consider upgrading to a newer PHP version.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-9993

Affected Products

Bei Fen – Wordpress Backup Plugin