CVE-2021-24174

HIGH

Database Backups WordPress Plugin <= 1.2.2.6 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-24174. PoCs published by 0xB9.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in WordPress Plugin Database Backups 1.2.2.6, allowing an attacker to trick an admin into creating a publicly accessible database backup. The backup can then be downloaded from a predictable URL.

Description

The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups.

Exploits (1)

exploitdb WORKING POC
by 0xB9 · htmlwebappsphp
https://www.exploit-db.com/exploits/49984

This exploit demonstrates a CSRF vulnerability in WordPress Plugin Database Backups 1.2.2.6, allowing an attacker to trick an admin into creating a publicly accessible database backup. The backup can then be downloaded from a predictable URL.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin Database Backups 1.2.2.6
No auth needed
Prerequisites: Admin user must be tricked into submitting the form
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 8.1
EPSS 0.0037
EPSS Percentile 59.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Details

CWE
CWE-352
Status published
Products (1)
database-backups_project/database-backups < 1.2.2.6
Published Apr 05, 2021
Tracked Since Feb 18, 2026