nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47979 CVE-2021-47979
HIGH
WordPress Plugin Backup and Restore 1.0.3 Arbitrary File Deletion
Record summary
CVE-2021-47979 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating parameters in AJAX requests. Attackers can send POST requests to admin-ajax.php with crafted file_name and folder_name parameters to delete arbitrary files from the WordPress installation directory.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Backup and RestoreBrowse Miniorange / Backup and Restore | CVE List | 1.0.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Backup and Restore 1.0.3 - Arbitrary File DeletionExploitDB exploitby Murat DEMİRCİNot analyzed1 file
References
5Product Referenceproduct
https://wordpress.org/plugins/backup-and-restore-for-wp ExploitDB-50503exploit
https://www.exploit-db.com/exploits/50503 Official Product Homepageproduct
https://www.miniorange.com/ VulnCheck Advisory: WordPress Plugin Backup and Restore 1.0.3 Arbitrary File DeletionThird-party advisory
https://www.vulncheck.com/advisories/wordpress-plugin-backup-and-restore-arbitrary-file-deletion