nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-20076 CVE-2016-20076
HIGH
WordPress Simple-Backup 2.7.11 Arbitrary File Deletion and Download
Record summary
CVE-2016-20076 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrary files and download sensitive files by manipulating the delete_backup_file and download_backup_file parameters in tools.php. Attackers can exploit insufficient input validation using directory traversal techniques to access wp-config.php, database dumps, and other sensitive files, or delete critical files .htaccess to expose backup directories.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 15, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Simple BackupBrowse ChrisHurst / Simple Backup | CVE List | 2.7.11 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Simple Backup 2.7.11 - Multiple VulnerabilitiesExploitDB exploitby PizzaHatHackerNot analyzed1 file
References
3ExploitDB-39883exploit
https://www.exploit-db.com/exploits/39883 VulnCheck Advisory: WordPress Simple-Backup 2.7.11 Arbitrary File Deletion and DownloadThird-party advisory
https://www.vulncheck.com/advisories/wordpress-simple-backup-arbitrary-file-deletion-and-download