CVE-2019-25224
CRITICAL 9.8EPSS 16.7%
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 16.68% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2025-07-25
- Updated
- 2026-04-08