PT-2025-40471 · Backupbolt · Backup Bolt

Jonas Benjamin Friedli

·

Published

2025-10-03

·

Updated

2025-10-03

·

CVE-2025-10306

CVSS v3.1

3.8

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4.1 via the process backup batch() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to download directories outside of the webroot and write backup zip files to arbitrary locations.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-10306

Affected Products

Backup Bolt