Cross-Site Request Forgery Vulnerability in Backup Bolt by WordPress
CVE-2025-49040
4.3MEDIUM
What is CVE-2025-49040?
A Cross-Site Request Forgery (CSRF) vulnerability in the Backup Bolt plugin allows attackers to send unauthorized commands to the application, potentially compromising user data and functionality. This flaw affects versions of Backup Bolt up to and including 1.4.1. Website owners are urged to review their installations and apply necessary security measures to mitigate this risk.
Affected Version(s)
Backup Bolt <= 1.4.1