OS Command Injection in WP Database Backup Plugin by WordPress
CVE-2019-25224
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 July 2025
What is CVE-2019-25224?
The WP Database Backup plugin for WordPress is susceptible to OS Command Injection vulnerabilities due to the mishandling of input in the mysqldump function. This flaw enables unauthenticated attackers to execute arbitrary commands on the underlying operating system, potentially compromising the server's security. It is crucial for users of affected versions to update to version 5.2 or later to mitigate this security risk and protect their installations.
Affected Version(s)
WP Database Backup – Unlimited Database & Files Backup by Backup for WP * < 5.2
References
EPSS Score
26% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved