XM-Backup

XM-Backup has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for XM-Backup has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Nguyen Xuan Chien. XM-Backup is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.3.2.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all XM-Backup vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2025-48109

XM-Backup <= 0.9.1 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Plugin Profile
Latestv0.9.1
0.0(0)
0/100
Last Updated
2012-05-19 (15y ago)
Active Installs
40+
Downloads
14,105
Requires WP
2.7.0+
Requires PHP
0+
Tested up to
WP 3.3.2
Created
2012-02-20 (15y ago)

This plugin will do a backup of your WordPress database and, or your files in wp-content/uploads and saves it somewhere safe. You can have the backup saved in your Dropbox account, a FTP account of your choise, your account with Online File Folder, or have the backup emailed to you (not recommended for large files). You can select to have the backups named the same every day or to have a date added to each file name. This plugin requires PHP, cURL, PHP compiled with ZIP support, and Oauth (for Dropbox). ** NO WARRANTY SUPPLIED! ** ** Make sure you test your Backups! **

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C