PT-2026-30901 · WordPress · Backup Migration

Rafał

·

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2025-14944

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Backup Migration plugin for WordPress versions up to and including 2.0.0
Description The Backup Migration plugin for WordPress is susceptible to unauthorized access due to a missing capability check on the initializeOfflineAjax function and insufficient nonce verification. The plugin validates requests against hardcoded tokens exposed in its JavaScript code, allowing unauthenticated attackers to initiate the backup upload queue processing. This could lead to unintended backup transfers to configured cloud storage and resource depletion.
Recommendations Update to a version later than 2.0.0

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14944

Affected Products

Backup Migration