🔐 CVE Alert

CVE-2019-25224

CRITICAL 9.8

WP Database Backup < 5.2 - Unauthenticated OS Command Injection

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.

CWE CWE-78
Vendor databasebackup
Product wp database backup – unlimited database & files backup by backup for wp
Published Jul 25, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for databasebackup wp database backup – unlimited database & files backup by backup for wp

Be the first to know when new critical vulnerabilities affecting databasebackup wp database backup – unlimited database & files backup by backup for wp are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

databasebackup / WP Database Backup – Unlimited Database & Files Backup by Backup for WP
0 < 5.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/d21cf285-9d75-43a2-9e81-67116f0bf896?source=cve wordfence.com: https://www.wordfence.com/blog/2019/05/os-command-injection-vulnerability-patched-in-wp-database-backup-plugin/ plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/2078035/wp-database-backup blog.sucuri.net: https://blog.sucuri.net/2019/06/os-command-injection-in-wp-database-backup.html packetstormsecurity.com: https://packetstormsecurity.com/files/153781/ raw.githubusercontent.com: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/wp_db_backup_rce.rb