๐Ÿ” CVE Alert

CVE-2025-24651

UNKNOWN 0.0

WordPress WebToffee WP Backup and Migration plugin <= 1.5.3 - Sensitive Data Exposure vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Retrieve Embedded Sensitive Data.This issue affects WordPress Backup & Migration: from n/a through <= 1.5.3.

CWE CWE-532
Vendor webtoffee
Product wordpress backup & migration
Published Apr 17, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for webtoffee wordpress backup & migration

Be the first to know when new unknown vulnerabilities affecting webtoffee wordpress backup & migration are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

WebToffee / WordPress Backup & Migration
0 โ‰ค 1.5.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/wp-migration-duplicator/vulnerability/wordpress-webtoffee-wp-backup-and-migration-plugin-1-5-3-sensitive-data-exposure-vulnerability?_s_id=cve

Credits

savphill | Patchstack Bug Bounty Program