CVE-2021-24174

HIGH

Database-backups < 1.2.2.6 - CSRF

Title source: rule

Description

The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups.

Exploits (1)

exploitdb WORKING POC
by 0xB9 · htmlwebappsphp
https://www.exploit-db.com/exploits/49984

Scores

CVSS v3 8.1
EPSS 0.0037
EPSS Percentile 59.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Details

CWE
CWE-352
Status published
Products (1)
database-backups_project/database-backups < 1.2.2.6
Published Apr 05, 2021
Tracked Since Feb 18, 2026