Backup Migration

Backup Migration has 19 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 19 are fixed as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 9.8 out of 10. Severity breakdown: 3 critical and 7 high. 2023 was the busiest year with 10 disclosures.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 4 of the records (21%). Other recurring categories include Missing Authorization, Cross-Site Request Forgery (CSRF).

Every one of the 19 issues recorded for Backup Migration has a vendor fix available, so running the current release closes all known holes.

16 independent researchers contributed these findings, most of them (2) reported by Chloe Chamberland. Backup Migration is installed on roughly 80,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

01234567891001.12.2020Today17.11.20215.5Backup Migration <= 1.1.5 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 5.5 · 17.11.202110.05.20237.5Backup Migration <= 1.2.8 - Sensitive Information Exposure CVSS 7.5 · 10.05.202327.07.20234.3Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function CVSS 4.3 · 27.07.20234.3Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function CVSS 4.3 · 27.07.202305.09.20234.3Backup Migration <= 1.2.9 - Cross-Site Request Forgery CVSS 4.3 · 05.09.202330.11.20237.5Backup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure CVSS 7.5 · 30.11.202307.12.20239.8Backup Migration <= 1.3.5 - Unauthenticated Sensitive Information Exposure CVSS 9.8 · 07.12.202311.12.20239.8Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution CVSS 9.8 · 11.12.202322.12.20239.8Backup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File Deletion CVSS 9.8 · 22.12.20238.1Backup Migration 1.0.8 - 1.3.9 - Remote File Inclusion via content-dir CVSS 8.1 · 22.12.20237.2Backup Migration <= 1.3.9 - Authenticated (Admin+) OS Command Injection via url CVSS 7.2 · 22.12.202310.04.20244.3Inisev Analyst Module <= Various Versions - Missing Authorization CVSS 4.3 · 10.04.202417.04.20245.3Backup Migration <= 1.4.3 - Information Exposure via Log Files CVSS 5.3 · 17.04.202403.01.20258.8Backup Migration <= 1.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialize_replace' CVSS 8.8 · 03.01.202503.11.20257.5Backup Migration <= 1.4.9 - Information Exposure to Unauthenticated Back-up Download CVSS 7.5 · 03.11.202506.04.20265.3Backup Migration <= 2.0.0 - Missing Authorization to Unauthenticated Backup Upload to Offline Storage CVSS 5.3 · 06.04.202608.04.20265.3BackupBliss – Backup & Migration with Free Cloud Storage <= 2.1.1 - Unauthenticated Information Exposure CVSS 5.3 · 08.04.202604.08.20267.2Backup Migration <= 2.1.5.1 - Authenticated (Administrator+) OS Command Injection via 'file' Parameter CVSS 7.2 · 04.08.202613.08.20264.7Backup Migration <= 2.1.6 - Authenticated (Administrator+) Privilege Escalation CVSS 4.7 · 13.08.2026

Strategic Overview

Avg CVSSMedium
6.7/ 10
Patch Coverage100%
Open

0

Fixed

19

Get automatic notifications for all Backup Migration vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2023-6972

Backup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File Deletion

Read the full analysis

Vulnerability Records

19 records
2026-08-13 00:00CVE-2026-18216
4.7
Medium
Thanh Lam TangYes
2026-08-04 18:04CVE-2026-7693
7.2
High
at1asYes
2026-04-08 00:00CVE-2026-39480
5.3
Medium
ch4r0nYes
2026-04-06 00:00CVE-2025-14944
5.3
Medium
0N0iseYes
2025-11-03 00:00CVE-2025-12394
7.5
High
ymmfty0Yes
2025-01-03 00:00CVE-2024-10932
8.8
High
WebbernautYes
2024-04-17 00:00CVE-2024-32686
5.3
Medium
emadYes
2024-04-10 00:00CVE-2024-31435
4.3
Medium
Dhabaleshwar DasYes
2023-12-22 00:00CVE-2023-6972
9.8
Critical
Hiroho ShimadaYes
2023-12-22 00:00CVE-2023-6971
8.1
High
Hiroho ShimadaYes
Showing 1–10 of 19 reports
Backup Migration banner
Latestv2.1.7

Backup Migration

Inisev

Author

Inisev

4.9(1,332)
98/100
Last Updated
2026-08-11 (1mo ago)
Active Installs
80,000+
Downloads
2,586,787
Requires WP
4.6+
Requires PHP
5.6+
Tested up to
WP 7.0.4
Created
2020-12-01 (6y ago)

TL;DR: 🚀 Lightning fast backups 🪶 Lightweight – just over 1MB ⚡ Super-quick migration with only a few clicks 🎯 Incredibly easy to use – no tech skills required ☁️ Many free storage options: Google Drive, Dropbox, OneDrive, pCloud, Amazon S3 & more 🔒 Exclusive own storage solution with 1GB of free space – unique on the market! 👉 Try it out instantly on a live demo — Creating a backup of your site has never been easier! Simply install the plugin, click on “Create backup now” – done. Website migration is just as easy and FREE, with just two clicks! Wide range of available cloud storage locations: Google Drive, Dropbox, OneDrive, Amazon S3, Wasabi, pCloud, SFTP & FTP, and free cloud storage BackupBliss. You can also schedule backups, e.g. define that a backup should be taken automatically every week (or every day/month). Use a wide choice of configuration options: Define exactly which files / databases should be in the backup, and which should not Define where the backup will be stored (store locally and/or backup to cloud) Define what name your backup should have, in which instances you should receive a notification email, and much more Additional advanced features included in the premium: smart exclusion rules, Tar and GZip compression methods, full email notifications, automatic backups before updates, and more. This plugin is all in one solution if you need to migrate your site to another host or just restore the local backup. Note: This (free) version is limited to backups of 4GB in size, due to native WordPress ZIP limitations. For unlimited sizes and increased stability for larger sites, please have a look at the Premium Plugin. The code of this free plugin is licensed under GPLv3, however, we claim rights to other content. Please read the full Terms of Use that touch other points as well and apply in entirety. If any questions come up, please ask us in the Support Forum – we’re always happy to help!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C