Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2016-20076 3 Chrishurst, Mywebsiteadvisor, Wordpress 3 Simple Backup, Simple Backup, Wordpress 2026-10-01 7.5 High
WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrary files and download sensitive files by manipulating the delete_backup_file and download_backup_file parameters in tools.php. Attackers can exploit insufficient input validation using directory traversal techniques to access wp-config.php, database dumps, and other sensitive files, or delete critical files .htaccess to expose backup directories.
CVE-2015-10134 1 Mywebsiteadvisor 1 Simple Backup 2026-04-08 7.5 High
The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-config.php file from the affected site.