Cross-Site Scripting Vulnerability in Nifty Backups by NickDuncan
CVE-2025-52763

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 October 2025

What is CVE-2025-52763?

The Nifty Backups plugin from NickDuncan contains a reflected Cross-Site Scripting (XSS) vulnerability that occurs due to improper neutralization of user input during web page generation. This flaw could allow an attacker to inject hostile scripts into web pages viewed by users, compromising their data and account security. Affected versions include all prior to and including 1.08. Users are advised to update to the latest version and implement security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

Nifty Backups 0 <= 1.08

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.