Missing Authorization Vulnerability in Backup Migration Plugin for WordPress
CVE-2025-14944
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 April 2026
What is CVE-2025-14944?
The Backup Migration plugin for WordPress is susceptible to a missing authorization vulnerability affecting all versions up to and including 2.0.0. This issue stems from inadequate capability checks on the 'initializeOfflineAjax' function and the absence of proper nonce verification. As a result, attackers can exploit the endpoint, which only validates against hardcoded tokens found in the plugin's JavaScript, to initiate backup uploads and potentially execute unauthorized file transfers to cloud storage. This vulnerability poses a risk of resource exhaustion and unintended data transfers for those using the plugin.
Affected Version(s)
BackupBliss – Backup & Migration with Free Cloud Storage 0 <= 2.0.0