PT-2026-41465 · Miniorange · Backuprestore

Murat Demirci

·

Published

2026-05-16

·

Updated

2026-05-16

·

CVE-2021-47979

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating parameters in AJAX requests. Attackers can send POST requests to admin-ajax.php with crafted file name and folder name parameters to delete arbitrary files from the WordPress installation directory.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-47979

Affected Products

Backuprestore