Backup and Move Plugin

Backup and Move Plugin has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Backup and Move Plugin has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Nguyen Xuan Chien. Backup and Move Plugin is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.0.5.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Backup and Move Plugin vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2025-53246

Backup and Move <= 0.1 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Plugin Profile
Latestv0.1

Backup and Move Plugin

Gaurav Aggarwal

Author

Gaurav Aggarwal

3.0(6)
60/100
Last Updated
2011-08-21 (15y ago)
Active Installs
100+
Downloads
45,118
Requires WP
3.0+
Requires PHP
0+
Tested up to
WP 3.0.5
Created
2011-02-07 (16y ago)

Backup And Move plugin allow blog administrators to create a complete backup of their blog and easy option for restore it on a different server, domain, location, etc .This plugin is very usefull for non technical users who wants to shift their wordpress blog. This plugin can make all the transitions of moving a wordpress blog , creating a complete backup and restoring a previous backup very simple and smooth. Save restore.php by clicking here. A separate backup can be created and send to users’s email id as attachment. User can administrate backups i.e delete , download and overwrite. To restore a backup simply place .zip backup file in a directory along with restore.php and visit restore.php from browser. Provide restore.php with all required credentials and wait for plugin to restore . That’s it start bloging. P.S everything will be restored like blogs, posts, links , etc.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C